Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
lK1DKi27B4.dll

Overview

General Information

Sample name:lK1DKi27B4.dll
(renamed file extension from exe to dll, renamed because original name is a hash value)
Original sample name:d908e4fef54e64e1e5d8a2a91851a2f5794a2ba625690e8e30911ca06f9d2b8b.exe
Analysis ID:1524003
MD5:0246f502105fb05afbebb9901642cba0
SHA1:aadccd1ad344910c4cf83845eff287193c61cb08
SHA256:d908e4fef54e64e1e5d8a2a91851a2f5794a2ba625690e8e30911ca06f9d2b8b
Tags:exeRhysidauser-JAMESWT_MHT
Infos:

Detection

Score:76
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for dropped file
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
System process connects to network (likely due to code injection or exploit)
AI detected suspicious sample
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Dropped file seen in connection with other malware
Drops PE files
Found dropped PE file which has not been started or loaded
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
Sample execution stops while process was sleeping (likely an evasion)

Classification

  • System is w10x64
  • loaddll64.exe (PID: 6856 cmdline: loaddll64.exe "C:\Users\user\Desktop\lK1DKi27B4.dll" MD5: 763455F9DCB24DFEECC2B9D9F8D46D52)
    • conhost.exe (PID: 6876 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • cmd.exe (PID: 6992 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",#1 MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • rundll32.exe (PID: 7088 cmdline: rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",#1 MD5: EF3179D498793BF4234F708D3BE28633)
        • rundll32.exe (PID: 4208 cmdline: rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dll MD5: EF3179D498793BF4234F708D3BE28633)
    • rundll32.exe (PID: 7020 cmdline: rundll32.exe C:\Users\user\Desktop\lK1DKi27B4.dll,start MD5: EF3179D498793BF4234F708D3BE28633)
      • rundll32.exe (PID: 2008 cmdline: rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dll MD5: EF3179D498793BF4234F708D3BE28633)
    • rundll32.exe (PID: 6212 cmdline: rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",start MD5: EF3179D498793BF4234F708D3BE28633)
      • rundll32.exe (PID: 4592 cmdline: rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dll MD5: EF3179D498793BF4234F708D3BE28633)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Users\user\AppData\Local\Temp\tmpf193.dllAvira: detection malicious, Label: TR/AVI.Agent.yfqhy
Source: C:\Users\user\AppData\Local\Temp\tmpf193.dllReversingLabs: Detection: 39%
Source: lK1DKi27B4.dllReversingLabs: Detection: 54%
Source: Submited SampleIntegrated Neural Analysis Model: Matched 96.4% probability
Source: lK1DKi27B4.dllStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT

Networking

barindex
Source: C:\Windows\System32\rundll32.exeNetwork Connect: 5.252.177.228 443Jump to behavior
Source: C:\Windows\System32\rundll32.exeNetwork Connect: 85.239.52.252 443Jump to behavior
Source: C:\Windows\System32\rundll32.exeNetwork Connect: 80.87.206.189 443Jump to behavior
Source: Joe Sandbox ViewASN Name: MIVOCLOUDMD MIVOCLOUDMD
Source: Joe Sandbox ViewASN Name: PINDC-ASRU PINDC-ASRU
Source: Joe Sandbox ViewASN Name: RAINBOW-HKRainbownetworklimitedHK RAINBOW-HKRainbownetworklimitedHK
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 5.252.177.228
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 80.87.206.189
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: unknownTCP traffic detected without corresponding DNS query: 85.239.52.252
Source: C:\Windows\System32\rundll32.exeCode function: 3_2_00007FFE133239A0 recv,3_2_00007FFE133239A0
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49865
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49864
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49863
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49862
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49861
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49860
Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49859
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49858
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49857
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49856
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49855
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
Source: unknownNetwork traffic detected: HTTP traffic on port 49841 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49854
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49853
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49852
Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49851
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49850
Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49858 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49849
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49848
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49847
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49846
Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49845
Source: unknownNetwork traffic detected: HTTP traffic on port 49869 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49844
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49842
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49841
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49840
Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49839
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49838
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
Source: unknownNetwork traffic detected: HTTP traffic on port 49847 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49870 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49853 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49845 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49868 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
Source: unknownNetwork traffic detected: HTTP traffic on port 49862 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49851 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
Source: unknownNetwork traffic detected: HTTP traffic on port 49863 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49857 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49873
Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49872
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49870
Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 49846 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49869
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 49792 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49868
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49867
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49866
Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49849 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49866 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49861 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49844 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49873 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49850 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49856 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49867 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
Source: unknownNetwork traffic detected: HTTP traffic on port 49865 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
Source: unknownNetwork traffic detected: HTTP traffic on port 49842 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49767 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
Source: unknownNetwork traffic detected: HTTP traffic on port 49848 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49838 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49854 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49832 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Temp\tmpf193.dll C9920E995FBC98CD3883EF4C4520300D5E82BAB5D2A5C781E9E9FE694A43E82F
Source: classification engineClassification label: mal76.evad.winDLL@16/1@0/3
Source: C:\Windows\System32\rundll32.exeMutant created: NULL
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6876:120:WilError_03
Source: C:\Windows\System32\rundll32.exeFile created: C:\Users\user\AppData\Local\Temp\tmpf193.dllJump to behavior
Source: lK1DKi27B4.dllStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Windows\System32\loaddll64.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\lK1DKi27B4.dll,start
Source: lK1DKi27B4.dllReversingLabs: Detection: 54%
Source: unknownProcess created: C:\Windows\System32\loaddll64.exe loaddll64.exe "C:\Users\user\Desktop\lK1DKi27B4.dll"
Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",#1
Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\lK1DKi27B4.dll,start
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",#1
Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",start
Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dll
Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dll
Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dll
Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",#1Jump to behavior
Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\Desktop\lK1DKi27B4.dll,startJump to behavior
Source: C:\Windows\System32\loaddll64.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",startJump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",#1Jump to behavior
Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dllJump to behavior
Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dllJump to behavior
Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dllJump to behavior
Source: C:\Windows\System32\loaddll64.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\loaddll64.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\loaddll64.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\loaddll64.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\loaddll64.exeSection loaded: kernel.appcore.dllJump to behavior
Source: lK1DKi27B4.dllStatic PE information: Image base 0x180000000 > 0x60000000
Source: lK1DKi27B4.dllStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT
Source: lK1DKi27B4.dllStatic PE information: real checksum: 0xefc6 should be: 0x1e064
Source: tmpf193.dll.3.drStatic PE information: real checksum: 0x7024 should be: 0x7b45
Source: C:\Windows\System32\rundll32.exeFile created: C:\Users\user\AppData\Local\Temp\tmpf193.dllJump to dropped file
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 180000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 3600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 14400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 32400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 57600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 90000000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 180000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 3600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 14400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 32400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 57600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 90000000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 180000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 3600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 14400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 32400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 57600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 90000000Jump to behavior
Source: C:\Windows\System32\rundll32.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\tmpf193.dllJump to dropped file
Source: C:\Windows\System32\loaddll64.exe TID: 6852Thread sleep time: -120000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7040Thread sleep count: 48 > 30Jump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7040Thread sleep time: -8640000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7040Thread sleep time: -3600000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7040Thread sleep time: -14400000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7040Thread sleep time: -32400000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7040Thread sleep time: -57600000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7040Thread sleep time: -90000000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7096Thread sleep count: 48 > 30Jump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7096Thread sleep time: -8640000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7096Thread sleep time: -3600000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7096Thread sleep time: -14400000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7096Thread sleep time: -32400000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7096Thread sleep time: -57600000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 7096Thread sleep time: -90000000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 6196Thread sleep count: 48 > 30Jump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 6196Thread sleep time: -8640000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 6196Thread sleep time: -3600000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 6196Thread sleep time: -14400000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 6196Thread sleep time: -32400000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 6196Thread sleep time: -57600000s >= -30000sJump to behavior
Source: C:\Windows\System32\rundll32.exe TID: 6196Thread sleep time: -90000000s >= -30000sJump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\loaddll64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 180000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 3600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 14400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 32400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 57600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 90000000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 180000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 3600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 14400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 32400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 57600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 90000000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 180000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 3600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 14400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 32400000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 57600000Jump to behavior
Source: C:\Windows\System32\rundll32.exeThread delayed: delay time: 90000000Jump to behavior
Source: rundll32.exe, 00000004.00000002.1735064178.000002013E718000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: rundll32.exe, 00000003.00000002.1735077118.000001F644E78000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllLL
Source: rundll32.exe, 00000005.00000002.1764661378.0000029C4AB78000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllpp

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\System32\rundll32.exeNetwork Connect: 5.252.177.228 443Jump to behavior
Source: C:\Windows\System32\rundll32.exeNetwork Connect: 85.239.52.252 443Jump to behavior
Source: C:\Windows\System32\rundll32.exeNetwork Connect: 80.87.206.189 443Jump to behavior
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",#1Jump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
111
Process Injection
1
Rundll32
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
21
Virtualization/Sandbox Evasion
LSASS Memory21
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)111
Process Injection
Security Account Manager1
System Information Discovery
SMB/Windows Admin SharesData from Network Shared Drive1
Ingress Tool Transfer
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
DLL Side-Loading
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 1524003 Sample: lK1DKi27B4.exe Startdate: 02/10/2024 Architecture: WINDOWS Score: 76 37 Antivirus detection for dropped file 2->37 39 Multi AV Scanner detection for dropped file 2->39 41 Multi AV Scanner detection for submitted file 2->41 43 AI detected suspicious sample 2->43 8 loaddll64.exe 1 2->8         started        process3 process4 10 rundll32.exe 8->10         started        14 rundll32.exe 8->14         started        17 cmd.exe 1 8->17         started        19 conhost.exe 8->19         started        dnsIp5 31 85.239.52.252, 443, 49732, 49733 RAINBOW-HKRainbownetworklimitedHK Russian Federation 10->31 33 80.87.206.189, 443, 49730, 49731 PINDC-ASRU Russian Federation 10->33 35 5.252.177.228, 443, 49734, 49735 MIVOCLOUDMD Moldova Republic of 10->35 29 C:\Users\user\AppData\Local\...\tmpf193.dll, PE32+ 10->29 dropped 21 rundll32.exe 10->21         started        45 System process connects to network (likely due to code injection or exploit) 14->45 23 rundll32.exe 14->23         started        25 rundll32.exe 1 17->25         started        file6 signatures7 process8 process9 27 rundll32.exe 25->27         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
lK1DKi27B4.dll54%ReversingLabsWin64.Backdoor.Supper
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\tmpf193.dll100%AviraTR/AVI.Agent.yfqhy
C:\Users\user\AppData\Local\Temp\tmpf193.dll39%ReversingLabsWin64.Trojan.Generic
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.214.172
truefalse
    unknown
    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs
    IPDomainCountryFlagASNASN NameMalicious
    5.252.177.228
    unknownMoldova Republic of
    39798MIVOCLOUDMDtrue
    80.87.206.189
    unknownRussian Federation
    34665PINDC-ASRUtrue
    85.239.52.252
    unknownRussian Federation
    134121RAINBOW-HKRainbownetworklimitedHKtrue
    Joe Sandbox version:41.0.0 Charoite
    Analysis ID:1524003
    Start date and time:2024-10-02 14:01:23 +02:00
    Joe Sandbox product:CloudBasic
    Overall analysis duration:0h 2m 43s
    Hypervisor based Inspection enabled:false
    Report type:full
    Cookbook file name:default.jbs
    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
    Number of analysed new started processes analysed:9
    Number of new started drivers analysed:0
    Number of existing processes analysed:0
    Number of existing drivers analysed:0
    Number of injected processes analysed:0
    Technologies:
    • HCA enabled
    • EGA enabled
    • AMSI enabled
    Analysis Mode:default
    Analysis stop reason:Timeout
    Sample name:lK1DKi27B4.dll
    (renamed file extension from exe to dll, renamed because original name is a hash value)
    Original Sample Name:d908e4fef54e64e1e5d8a2a91851a2f5794a2ba625690e8e30911ca06f9d2b8b.exe
    Detection:MAL
    Classification:mal76.evad.winDLL@16/1@0/3
    EGA Information:
    • Successful, ratio: 100%
    HCA Information:
    • Successful, ratio: 100%
    • Number of executed functions: 9
    • Number of non-executed functions: 0
    Cookbook Comments:
    • Stop behavior analysis, all processes terminated
    • Excluded IPs from analysis (whitelisted): 4.245.163.56
    • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, sls.update.microsoft.com, ctldl.windowsupdate.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
    • Not all processes where analyzed, report is missing behavior information
    • VT rate limit hit for: lK1DKi27B4.dll
    TimeTypeDescription
    08:02:13API Interceptor162x Sleep call for process: rundll32.exe modified
    08:02:16API Interceptor1x Sleep call for process: loaddll64.exe modified
    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
    85.239.52.252donbologniese.com_443_64s.exeGet hashmaliciousCobaltStrikeBrowse
      donbologniese.com_443_64s.exeGet hashmaliciousCobaltStrikeBrowse
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        bg.microsoft.map.fastly.netZAMOWIEN.EXE.exeGet hashmaliciousGuLoaderBrowse
        • 199.232.210.172
        7ffbfc130000.conhost2.dll.dllGet hashmaliciousUnknownBrowse
        • 199.232.214.172
        https://sportmansguilde.com/?https://www.office.comGet hashmaliciousUnknownBrowse
        • 199.232.210.172
        Axactor Microsoft - Introduksjonsm#U00f8te.msgGet hashmaliciousEvilProxyBrowse
        • 199.232.214.172
        http://Asm.alcateia.orgGet hashmaliciousHTMLPhisherBrowse
        • 199.232.214.172
        https://cnrsys.com/.jhg/#annQ3bttQ3bd0T2vTau5kZR3wh07xdaiiR3whi-5kZankyH05d0TQ3buGet hashmaliciousHTMLPhisherBrowse
        • 199.232.214.172
        Scan_doc_09_16_24_1120.exeGet hashmaliciousScreenConnect ToolBrowse
        • 199.232.214.172
        E_BILL9926378035.exeGet hashmaliciousScreenConnect ToolBrowse
        • 199.232.210.172
        https://maninhocontabilidade.com.br/pop/Webmail-iinet.zipGet hashmaliciousHTMLPhisherBrowse
        • 199.232.210.172
        E_BILL9926378035.exeGet hashmaliciousScreenConnect ToolBrowse
        • 199.232.214.172
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        MIVOCLOUDMDupdate.jsGet hashmaliciousNetSupport RATBrowse
        • 5.181.159.137
        MRSPBASd65554AB.dll.dllGet hashmaliciousUnknownBrowse
        • 94.158.245.136
        MRSPBASd65554AB.dll.dllGet hashmaliciousUnknownBrowse
        • 94.158.245.136
        Update.jsGet hashmaliciousNetSupport RATBrowse
        • 5.181.159.137
        ZWlwrTM9HK.exeGet hashmaliciousRemcosBrowse
        • 5.181.156.117
        Gez0dmj6yl.exeGet hashmaliciousDCRatBrowse
        • 94.158.244.70
        update.jsGet hashmaliciousNetSupport RATBrowse
        • 5.181.159.28
        17E503AEF3804C0513838FB4AE3E00F323B1260BF753D99DBF0AE415BA54DE11.exeGet hashmaliciousBdaejec, RaccoonBrowse
        • 194.180.191.241
        updates.jsGet hashmaliciousNetSupport RATBrowse
        • 194.180.191.69
        updates.jsGet hashmaliciousNetSupport RATBrowse
        • 94.158.245.103
        PINDC-ASRUhttps://trstwalsecu.com/Get hashmaliciousUnknownBrowse
        • 91.215.85.16
        https://metamaskinf.com/Get hashmaliciousUnknownBrowse
        • 91.215.85.79
        http://mygovau-service.com/Get hashmaliciousUnknownBrowse
        • 91.215.85.79
        PO-001.exeGet hashmaliciousFormBookBrowse
        • 91.215.85.23
        PO #86637.exeGet hashmaliciousFormBookBrowse
        • 91.215.85.23
        https://91.215.85.55Get hashmaliciousUnknownBrowse
        • 91.215.85.55
        file.exeGet hashmaliciousPhorpiexBrowse
        • 194.93.26.70
        invoice.exeGet hashmaliciousFormBookBrowse
        • 91.215.85.23
        Purchase order.exeGet hashmaliciousFormBookBrowse
        • 91.215.85.23
        Remittance advice.exeGet hashmaliciousFormBookBrowse
        • 91.215.85.23
        RAINBOW-HKRainbownetworklimitedHKnPyo7vtpRl.dllGet hashmaliciousUnknownBrowse
        • 45.86.230.68
        rdl3kBqbTy.dllGet hashmaliciousUnknownBrowse
        • 45.86.230.68
        nPyo7vtpRl.dllGet hashmaliciousUnknownBrowse
        • 45.86.230.68
        rdl3kBqbTy.dllGet hashmaliciousUnknownBrowse
        • 45.86.230.68
        file.exeGet hashmaliciousUnknownBrowse
        • 85.239.52.241
        file.exeGet hashmaliciousUnknownBrowse
        • 85.239.52.241
        Havarti.dllGet hashmaliciousUnknownBrowse
        • 45.86.230.68
        https://www.izmailovo.ru/contacts/Get hashmaliciousHTMLPhisherBrowse
        • 45.92.176.235
        http://iskhelp.co.uk/rd/5IFNPS23345ktRZ2482qejogtfkrk1638BHXWAAYQYFQDJLF6525/368L16Get hashmaliciousUnknownBrowse
        • 85.239.34.168
        app.exeGet hashmaliciousUnknownBrowse
        • 85.239.53.219
        No context
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        C:\Users\user\AppData\Local\Temp\tmpf193.dll7ffbfc130000.conhost2.dll.dllGet hashmaliciousUnknownBrowse
          nPyo7vtpRl.dllGet hashmaliciousUnknownBrowse
            rdl3kBqbTy.dllGet hashmaliciousUnknownBrowse
              nPyo7vtpRl.dllGet hashmaliciousUnknownBrowse
                rdl3kBqbTy.dllGet hashmaliciousUnknownBrowse
                  7ff6c1d70000.xxtlz.exeGet hashmaliciousUnknownBrowse
                    VOqg4bXfFS.dllGet hashmaliciousUnknownBrowse
                      tZlDJKdfV6.dllGet hashmaliciousUnknownBrowse
                        Y1kJT9dEK1.dllGet hashmaliciousUnknownBrowse
                          Havarti.dllGet hashmaliciousUnknownBrowse
                            Process:C:\Windows\System32\rundll32.exe
                            File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                            Category:dropped
                            Size (bytes):2560
                            Entropy (8bit):1.257085001705468
                            Encrypted:false
                            SSDEEP:12:etGSGQwU8O0ay2Y8qS6gK/H/ffk6Om2BXp:etGScU8O0ay2vqS6p/H/QvBXp
                            MD5:634A9AF8D3F2FA0D38820D577FB0FBEB
                            SHA1:CD6E84A3C4F81FC9DF8B82449DB8B2E87130E3FD
                            SHA-256:C9920E995FBC98CD3883EF4C4520300D5E82BAB5D2A5C781E9E9FE694A43E82F
                            SHA-512:ABCA2E016FF5A53395F95BA75C96F5BFA102086E92A8E2647BD2584A75E4A81A59596848D1ABFAB8E37981A6ADB021A35074D4DC99868CC30C9C4E2A4666C50A
                            Malicious:true
                            Antivirus:
                            • Antivirus: Avira, Detection: 100%
                            • Antivirus: ReversingLabs, Detection: 39%
                            Joe Sandbox View:
                            • Filename: 7ffbfc130000.conhost2.dll.dll, Detection: malicious, Browse
                            • Filename: nPyo7vtpRl.dll, Detection: malicious, Browse
                            • Filename: rdl3kBqbTy.dll, Detection: malicious, Browse
                            • Filename: nPyo7vtpRl.dll, Detection: malicious, Browse
                            • Filename: rdl3kBqbTy.dll, Detection: malicious, Browse
                            • Filename: 7ff6c1d70000.xxtlz.exe, Detection: malicious, Browse
                            • Filename: VOqg4bXfFS.dll, Detection: malicious, Browse
                            • Filename: tZlDJKdfV6.dll, Detection: malicious, Browse
                            • Filename: Y1kJT9dEK1.dll, Detection: malicious, Browse
                            • Filename: Havarti.dll, Detection: malicious, Browse
                            Reputation:moderate, very likely benign file
                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....f....r.....&"...(.....................................................@......$p....`... ...................................... ..?....0......................................................................................`0.. ............................text...p........................... ..`.edata..?.... ......................@..@.idata.......0......................@...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                            File type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                            Entropy (8bit):1.3730080047022892
                            TrID:
                            • Win64 Dynamic Link Library (generic) (102004/3) 86.43%
                            • Win64 Executable (generic) (12005/4) 10.17%
                            • Generic Win/DOS Executable (2004/3) 1.70%
                            • DOS Executable Generic (2002/1) 1.70%
                            • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.01%
                            File name:lK1DKi27B4.dll
                            File size:89'984 bytes
                            MD5:0246f502105fb05afbebb9901642cba0
                            SHA1:aadccd1ad344910c4cf83845eff287193c61cb08
                            SHA256:d908e4fef54e64e1e5d8a2a91851a2f5794a2ba625690e8e30911ca06f9d2b8b
                            SHA512:8e95d1065ed683b671ff8e5835f6d832027594c7eaafdfd5ef5c3d26ed01e500db0512096caf6c714791a53ba739bf942490c83261f2f24076850ac011f5dd57
                            SSDEEP:384:gWXQWPQUtdK3TQYIyTjWLH2CekEbZykA2nKTb8dEwEsH:g3dyL3ej1n/KTQqdsH
                            TLSH:2C93A862F261C8ADC52BF3F196C762B275F439590728396F4391A5F83F2993D1B34920
                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...'..f.N........&"...(.0..........@9....................................................`... ............................
                            Icon Hash:7ae282899bbab082
                            Entrypoint:0x180003940
                            Entrypoint Section:.text
                            Digitally signed:false
                            Imagebase:0x180000000
                            Subsystem:windows gui
                            Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LARGE_ADDRESS_AWARE, DEBUG_STRIPPED, DLL
                            DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT
                            Time Stamp:0x66868227 [Thu Jul 4 11:06:15 2024 UTC]
                            TLS Callbacks:
                            CLR (.Net) Version:
                            OS Version Major:4
                            OS Version Minor:0
                            File Version Major:4
                            File Version Minor:0
                            Subsystem Version Major:4
                            Subsystem Version Minor:0
                            Import Hash:6a1060e817f2dd8e2db1b1d07029ac5c
                            Instruction
                            push ebp
                            dec eax
                            mov ebp, esp
                            dec eax
                            sub esp, 20h
                            dec eax
                            mov dword ptr [ebp+10h], ecx
                            mov dword ptr [ebp+18h], edx
                            dec esp
                            mov dword ptr [ebp+20h], eax
                            cmp dword ptr [ebp+18h], 03h
                            jnbe 00007F67D092D803h
                            cmp dword ptr [ebp+18h], 02h
                            jnc 00007F67D092D7FCh
                            cmp dword ptr [ebp+18h], 00000000h
                            je 00007F67D092D7F6h
                            cmp dword ptr [ebp+18h], 01h
                            jne 00007F67D092D7F1h
                            mov ecx, 00000000h
                            call 00007F67D092DC40h
                            mov ecx, eax
                            call 00007F67D092DC29h
                            dec eax
                            mov eax, dword ptr [ebp+10h]
                            dec eax
                            mov dword ptr [000226C1h], eax
                            jmp 00007F67D092D7D3h
                            nop
                            mov eax, 00000001h
                            dec eax
                            add esp, 20h
                            pop ebp
                            ret
                            nop
                            nop
                            nop
                            nop
                            nop
                            nop
                            nop
                            nop
                            nop
                            nop
                            nop
                            push ebp
                            dec eax
                            sub esp, 00000240h
                            dec eax
                            lea ebp, dword ptr [esp+00000080h]
                            dec eax
                            mov dword ptr [ebp+000001D0h], ecx
                            dec eax
                            mov dword ptr [ebp+000001D8h], edx
                            inc esp
                            mov dword ptr [ebp+000001E0h], eax
                            dec esp
                            mov dword ptr [ebp+000001E8h], ecx
                            dec eax
                            cmp dword ptr [ebp+000001D0h], FFFFFFFFh
                            jne 00007F67D092D7DCh
                            mov eax, FFFFFFFFh
                            jmp 00007F67D092D8B3h
                            mov dword ptr [ebp-50h], 00000000h
                            mov dword ptr [ebp+000001BCh], 00000000h
                            jmp 00007F67D092D7EDh
                            mov eax, dword ptr [ebp+000001BCh]
                            dec eax
                            mov eax, dword ptr [ebp+eax*8-48h]
                            dec eax
                            cmp dword ptr [ebp+000001D0h], eax
                            je 00007F67D092D7E4h
                            NameVirtual AddressVirtual Size Is in Section
                            IMAGE_DIRECTORY_ENTRY_EXPORT0x270000x42.edata
                            IMAGE_DIRECTORY_ENTRY_IMPORT0x280000x850.idata
                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x00x0
                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x290000xc.reloc
                            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                            IMAGE_DIRECTORY_ENTRY_IAT0x282500x1d8.idata
                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                            .text0x10000x2f500x300037f8eecfe39194401dbac3a7c1c56c10False0.4117838541666667data5.457968090728284IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                            .data0x40000xa000xa00634a9af8d3f2fa0d38820d577fb0fbebFalse0.1640625PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows1.2570850017054678IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                            .rdata0x50000x1100x2000e32780154d4a86e51e0a0301cf96fc7False0.36328125data3.2847442780382976IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                            .bss0x60000x200500x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                            .edata0x270000x420x200fa3c406df5eb87a4ea8cde5cd404d450False0.123046875data0.6992317266973137IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                            .idata0x280000x8500xa00292e0dbff605f6a37700d204af178cefFalse0.3140625data3.7572216558531455IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                            .reloc0x290000xc0x200f31f27cadb3c557842599b1db61e752cFalse0.041015625data0.06116285224115448IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                            DLLImport
                            ADVAPI32.dllGetSidSubAuthority, GetSidSubAuthorityCount, GetTokenInformation, OpenProcessToken
                            KERNEL32.dllCloseHandle, CreateMutexA, CreatePipe, CreateProcessA, GetComputerNameA, GetCurrentProcess, GetExitCodeProcess, GetFileSize, GetModuleFileNameA, GetVersionExA, ReadFile, ReleaseMutex, SetHandleInformation, Sleep, TerminateProcess, VerSetConditionMask, VerifyVersionInfoA, WaitForSingleObject, WriteFile
                            msvcrt.dll_beginthread, exit, fclose, fopen, free, fwrite, getenv, malloc, memcpy, memset, rand, sprintf, srand, wcstombs, _time64
                            NETAPI32.dllNetApiBufferFree, NetGetJoinInformation
                            WS2_32.dllWSAStartup, __WSAFDIsSet, closesocket, connect, freeaddrinfo, getaddrinfo, htons, inet_addr, inet_ntop, ntohs, recv, select, send, socket
                            NameOrdinalAddress
                            start10x1800037e0
                            TimestampSource PortDest PortSource IPDest IP
                            Oct 2, 2024 14:02:13.988980055 CEST49730443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:13.989017963 CEST4434973080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:13.989109993 CEST49730443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:13.995409012 CEST49730443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:13.995423079 CEST4434973080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:13.995568991 CEST4434973080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:13.998209953 CEST49731443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:13.998306036 CEST4434973180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:13.998411894 CEST49731443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.000088930 CEST49731443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.000128984 CEST4434973180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.000174999 CEST4434973180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.108732939 CEST49732443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.108778954 CEST49733443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.108805895 CEST4434973285.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.108877897 CEST49732443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.108879089 CEST4434973385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.108947992 CEST49733443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.110239029 CEST49733443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.110275030 CEST49732443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.110282898 CEST4434973385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.110308886 CEST4434973285.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.110333920 CEST4434973385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.110419035 CEST4434973285.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.248013973 CEST49735443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.248017073 CEST49734443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.248096943 CEST443497355.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.248132944 CEST443497345.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.248183012 CEST49735443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.248209000 CEST49734443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.249057055 CEST49735443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.249062061 CEST49734443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.249093056 CEST443497355.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.249099016 CEST443497345.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.249205112 CEST443497355.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.249233961 CEST443497345.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.358747959 CEST49737443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.358755112 CEST49736443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.358772039 CEST4434973780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.358820915 CEST4434973680.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.358846903 CEST49737443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.358880997 CEST49736443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.359483957 CEST49737443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.359503984 CEST4434973780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.359580994 CEST4434973780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.359586954 CEST49736443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.359626055 CEST4434973680.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.359684944 CEST4434973680.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.468097925 CEST49738443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.468139887 CEST4434973885.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.468138933 CEST49739443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.468213081 CEST4434973985.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.468249083 CEST49738443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.468277931 CEST49739443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.468869925 CEST49739443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.468879938 CEST49738443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.468897104 CEST4434973885.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.468905926 CEST4434973985.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.468976021 CEST4434973885.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.469018936 CEST4434973985.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.582953930 CEST49740443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.583036900 CEST443497405.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.583065987 CEST49741443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.583100080 CEST443497415.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.583122969 CEST49740443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.583144903 CEST49741443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.584002018 CEST49741443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.584017992 CEST443497415.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.584069014 CEST443497415.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.584120035 CEST49740443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.584155083 CEST443497405.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.584238052 CEST443497405.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.686849117 CEST49742443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.686866999 CEST49743443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.686873913 CEST443497425.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.686903000 CEST443497435.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.686935902 CEST49742443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.686999083 CEST49743443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.687549114 CEST49742443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.687558889 CEST443497425.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.687576056 CEST49743443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:14.687660933 CEST443497435.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.687666893 CEST443497425.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.687693119 CEST443497435.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:14.796124935 CEST49744443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.796161890 CEST4434974480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.796215057 CEST49744443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.796304941 CEST49745443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.796408892 CEST4434974580.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.796489000 CEST49745443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.796664000 CEST49744443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.796680927 CEST4434974480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.796726942 CEST4434974480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.797224045 CEST49745443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:14.797266960 CEST4434974580.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.797297955 CEST4434974580.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:14.905606031 CEST49746443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.905684948 CEST4434974685.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.905752897 CEST49746443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.905874968 CEST49747443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.905976057 CEST4434974785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.906066895 CEST49747443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.911304951 CEST49746443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.911339998 CEST4434974685.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.911370039 CEST4434974685.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.912245035 CEST49747443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:14.912286043 CEST4434974785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:14.912317991 CEST4434974785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.015146971 CEST49748443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.015163898 CEST49749443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.015191078 CEST4434974880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.015279055 CEST4434974980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.015326023 CEST49748443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.015362978 CEST49749443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.016052961 CEST49749443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.016098976 CEST4434974980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.016134024 CEST4434974980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.016238928 CEST49748443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.016251087 CEST4434974880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.016355038 CEST4434974880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.124669075 CEST49750443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.124747992 CEST4434975085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.124820948 CEST49750443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.125093937 CEST49751443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.125191927 CEST4434975185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.125263929 CEST49751443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.126720905 CEST49750443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.126754999 CEST4434975085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.126827955 CEST4434975085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.127249956 CEST49751443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.127290964 CEST4434975185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.127326012 CEST4434975185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.272308111 CEST49752443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.272350073 CEST443497525.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.272406101 CEST49752443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.272694111 CEST49753443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.272732019 CEST443497535.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.272787094 CEST49753443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.273823023 CEST49752443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.273842096 CEST443497525.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.273921967 CEST443497525.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.274460077 CEST49753443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.274488926 CEST443497535.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.274569035 CEST443497535.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.390249968 CEST49754443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.390341043 CEST4434975485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.390342951 CEST49755443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.390399933 CEST4434975585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.390429020 CEST49754443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.390445948 CEST49755443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.391942978 CEST49754443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.391979933 CEST4434975485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.392095089 CEST4434975485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.392118931 CEST49755443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.392138958 CEST4434975585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.392196894 CEST4434975585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.499573946 CEST49756443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.499633074 CEST443497565.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.499707937 CEST49756443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.500029087 CEST49757443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.500123024 CEST443497575.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.500194073 CEST49757443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.501094103 CEST49756443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.501111031 CEST443497565.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.501230001 CEST443497565.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.501547098 CEST49757443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.501583099 CEST443497575.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.501640081 CEST443497575.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.612538099 CEST49758443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.612607002 CEST4434975880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.612696886 CEST49758443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.615868092 CEST49759443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.615916014 CEST4434975980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.615967989 CEST49759443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.622816086 CEST49758443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.622845888 CEST4434975880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.622957945 CEST4434975880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.628026009 CEST49759443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.628074884 CEST4434975980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.628134012 CEST4434975980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.736188889 CEST49760443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.736242056 CEST443497605.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.736311913 CEST49760443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.736593008 CEST49761443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.736681938 CEST443497615.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.736757040 CEST49761443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.756129026 CEST49760443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.756148100 CEST443497605.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.756253958 CEST443497605.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.756700993 CEST49761443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:15.756781101 CEST443497615.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.757006884 CEST443497615.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:15.859030008 CEST49762443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.859072924 CEST4434976280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.859143972 CEST49762443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.861088037 CEST49763443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.861155987 CEST4434976380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.861221075 CEST49763443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.862011909 CEST49763443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.862042904 CEST4434976380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.862164021 CEST4434976380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.862715006 CEST49762443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:15.862741947 CEST4434976280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.862847090 CEST4434976280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:15.993990898 CEST49764443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.994048119 CEST4434976485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.994117975 CEST49764443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.994394064 CEST49765443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:15.994488955 CEST4434976585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:15.994555950 CEST49765443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.010574102 CEST49764443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.010593891 CEST4434976485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.010858059 CEST4434976485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.011307001 CEST49765443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.011385918 CEST4434976585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.011503935 CEST4434976585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.126410961 CEST49766443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.126491070 CEST443497665.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.126518965 CEST49767443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.126549959 CEST443497675.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.126579046 CEST49766443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.126589060 CEST49767443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.130131006 CEST49766443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.130172014 CEST443497665.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.130294085 CEST443497665.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.133582115 CEST49767443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.133594990 CEST443497675.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.133704901 CEST443497675.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.233730078 CEST49768443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.233766079 CEST4434976880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.233843088 CEST49768443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.234404087 CEST49768443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.234414101 CEST4434976880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.234519005 CEST4434976880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.249285936 CEST49769443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.249382019 CEST4434976980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.249480963 CEST49769443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.249901056 CEST49769443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.249941111 CEST4434976980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.249983072 CEST4434976980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.343283892 CEST49770443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.343326092 CEST4434977085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.343416929 CEST49770443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.344394922 CEST49770443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.344413996 CEST4434977085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.344520092 CEST4434977085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.358732939 CEST49771443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.358781099 CEST4434977185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.358846903 CEST49771443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.359343052 CEST49771443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.359363079 CEST4434977185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.359433889 CEST4434977185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.452445030 CEST49772443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.452481985 CEST4434977280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.452549934 CEST49772443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.453058958 CEST49772443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.453073025 CEST4434977280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.453181982 CEST4434977280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.468141079 CEST49773443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.468231916 CEST4434977380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.468311071 CEST49773443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.468719959 CEST49773443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.468755007 CEST4434977380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.468810081 CEST4434977380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.561917067 CEST49774443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.562006950 CEST4434977485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.562093019 CEST49774443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.562706947 CEST49774443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.562741041 CEST4434977485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.562796116 CEST4434977485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.577440977 CEST49775443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.577476025 CEST4434977585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.577544928 CEST49775443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.578128099 CEST49775443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.578146935 CEST4434977585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.578193903 CEST4434977585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.671391010 CEST49776443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.671478987 CEST443497765.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.671574116 CEST49776443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.672267914 CEST49776443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.672307968 CEST443497765.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.672431946 CEST443497765.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.686805010 CEST49777443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.686850071 CEST443497775.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.686913013 CEST49777443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.687431097 CEST49777443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:16.687442064 CEST443497775.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.687498093 CEST443497775.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:16.780548096 CEST49778443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.780580044 CEST4434977880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.780635118 CEST49778443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.781065941 CEST49778443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.781081915 CEST4434977880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.781199932 CEST4434977880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.796134949 CEST49779443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.796185017 CEST4434977980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.796251059 CEST49779443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.796622992 CEST49779443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:16.796648979 CEST4434977980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.796698093 CEST4434977980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:16.889905930 CEST49780443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.890001059 CEST4434978085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.890104055 CEST49780443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.890631914 CEST49780443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.890671015 CEST4434978085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.890782118 CEST4434978085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.905498028 CEST49781443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.905514002 CEST4434978185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.905874968 CEST49781443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.906366110 CEST49781443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:16.906375885 CEST4434978185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:16.906429052 CEST4434978185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.012861013 CEST49782443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.012922049 CEST443497825.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.013025045 CEST49782443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.014257908 CEST49782443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.014273882 CEST443497825.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.014410973 CEST443497825.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.015052080 CEST49783443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.015149117 CEST443497835.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.015315056 CEST49783443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.015449047 CEST49784443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.015496969 CEST4434978485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.015564919 CEST49784443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.015825033 CEST49783443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.015862942 CEST443497835.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.015912056 CEST443497835.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.016860008 CEST49784443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.016884089 CEST4434978485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.017003059 CEST4434978485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.124254942 CEST49785443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.124345064 CEST443497855.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.124375105 CEST49786443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.124394894 CEST443497865.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.124423981 CEST49785443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.124459982 CEST49787443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.124485016 CEST49786443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.124532938 CEST443497875.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.124949932 CEST49786443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.124980927 CEST49787443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.124984980 CEST443497865.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.125097036 CEST443497865.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.125552893 CEST49785443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.125580072 CEST443497855.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.125653028 CEST49787443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.125686884 CEST443497875.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.125689030 CEST443497855.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.125741005 CEST443497875.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.233782053 CEST49788443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.233876944 CEST4434978880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.233966112 CEST49789443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.233966112 CEST49790443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.233968973 CEST49788443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.234003067 CEST4434978980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.234018087 CEST4434979080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.234076023 CEST49789443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.234400988 CEST49790443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.234543085 CEST49788443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.234555960 CEST49789443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.234569073 CEST4434978980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.234580040 CEST4434978880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.234675884 CEST4434978880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.234724998 CEST4434978980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.234875917 CEST49790443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.234885931 CEST4434979080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.234911919 CEST4434979080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.343230009 CEST49791443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.343317032 CEST4434979185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.343333960 CEST49793443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.343339920 CEST49792443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.343362093 CEST4434979385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.343380928 CEST443497925.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.343425989 CEST49793443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.343434095 CEST49791443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.343440056 CEST49792443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.344460011 CEST49791443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.344496965 CEST4434979185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.344538927 CEST49793443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.344547987 CEST4434979185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.344564915 CEST4434979385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.344670057 CEST4434979385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.344810963 CEST49792443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.344825983 CEST443497925.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.344944000 CEST443497925.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.452511072 CEST49795443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.452543020 CEST443497955.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.452578068 CEST49794443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.452622890 CEST4434979480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.452629089 CEST49796443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.452651978 CEST443497965.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.452673912 CEST49795443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.452712059 CEST49794443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.452822924 CEST49796443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.453303099 CEST49795443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.453315020 CEST443497955.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.453341007 CEST49794443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.453380108 CEST4434979480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.453394890 CEST443497955.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.453485966 CEST4434979480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.453615904 CEST49796443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.453625917 CEST443497965.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.453670979 CEST443497965.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.561920881 CEST49798443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.561973095 CEST4434979880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.562005997 CEST49797443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.562026024 CEST49799443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.562040091 CEST49798443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.562093973 CEST4434979785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.562117100 CEST4434979980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.562169075 CEST49797443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.562186956 CEST49799443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.562694073 CEST49798443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.562722921 CEST4434979880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.562796116 CEST4434979880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.563041925 CEST49797443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.563079119 CEST4434979785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.563189983 CEST4434979785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.563421011 CEST49799443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.563462019 CEST4434979980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.563493967 CEST4434979980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.673929930 CEST49800443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.674021959 CEST4434980085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.674120903 CEST49800443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.674514055 CEST49801443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.674556017 CEST443498015.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.674612999 CEST49801443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.675348997 CEST49802443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.675379992 CEST4434980285.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.675677061 CEST49802443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.688251019 CEST49800443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.688287973 CEST4434980085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.688309908 CEST49801443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.688332081 CEST443498015.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.688338995 CEST4434980085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.688384056 CEST443498015.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.689537048 CEST49802443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.689558983 CEST4434980285.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.689589977 CEST4434980285.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.796304941 CEST49803443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.796349049 CEST4434980380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.796408892 CEST49805443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.796432018 CEST49804443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.796439886 CEST443498055.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.796463966 CEST49803443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.796483994 CEST443498045.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.796497107 CEST49805443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.796561003 CEST49804443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.797425032 CEST49803443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.797435045 CEST4434980380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.797461033 CEST49805443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.797472000 CEST443498055.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.797509909 CEST443498055.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.797826052 CEST49804443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:17.797842026 CEST443498045.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.797884941 CEST443498045.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:17.798137903 CEST4434980380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.905744076 CEST49806443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.905839920 CEST4434980685.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.905941010 CEST49808443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.905967951 CEST4434980880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.905992031 CEST49806443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.906095982 CEST49808443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.906147003 CEST49807443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.906203032 CEST4434980780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.906251907 CEST49807443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.906675100 CEST49808443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.906707048 CEST4434980880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.906819105 CEST4434980880.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.907017946 CEST49806443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:17.907042027 CEST4434980685.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.907080889 CEST4434980685.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:17.907136917 CEST49807443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:17.907152891 CEST4434980780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:17.907188892 CEST4434980780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.015233040 CEST49809443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.015289068 CEST4434980985.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.015369892 CEST49809443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.015952110 CEST49810443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.015991926 CEST49811443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.016041040 CEST4434981185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.016047001 CEST4434981080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.016098022 CEST49811443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.016138077 CEST49810443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.017273903 CEST49809443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.017296076 CEST4434980985.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.017415047 CEST4434980985.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.017988920 CEST49811443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.018003941 CEST4434981185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.018050909 CEST4434981185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.019061089 CEST49810443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.019094944 CEST4434981080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.019134998 CEST4434981080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.124501944 CEST49812443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.124588966 CEST4434981285.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.124695063 CEST49812443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.125449896 CEST49812443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.125487089 CEST4434981285.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.125576973 CEST4434981285.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.234359026 CEST49813443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.234404087 CEST443498135.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.234477043 CEST49813443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.243129015 CEST49814443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.243175983 CEST4434981485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.243244886 CEST49814443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.243525982 CEST49815443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.243556976 CEST4434981585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.243626118 CEST49815443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.244496107 CEST49813443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.244515896 CEST443498135.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.244627953 CEST443498135.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.245367050 CEST49814443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.245381117 CEST4434981485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.245426893 CEST4434981485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.246028900 CEST49815443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.246049881 CEST4434981585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.246093035 CEST4434981585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.359035015 CEST49816443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.359092951 CEST443498165.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.359159946 CEST49816443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.359810114 CEST49817443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.359846115 CEST443498175.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.359891891 CEST49817443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.360331059 CEST49818443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.360398054 CEST4434981885.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.360460997 CEST49818443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.364763975 CEST49816443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.364782095 CEST443498165.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.364870071 CEST443498165.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.365534067 CEST49817443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.365550041 CEST443498175.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.365616083 CEST443498175.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.366548061 CEST49818443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.366580009 CEST4434981885.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.366621017 CEST4434981885.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.476676941 CEST49819443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.476743937 CEST443498195.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.476818085 CEST49819443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.545483112 CEST49820443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.545566082 CEST4434982080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.545651913 CEST49820443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.545913935 CEST49821443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.545955896 CEST4434982180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.545999050 CEST49821443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.547722101 CEST49819443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.547766924 CEST443498195.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.547816038 CEST443498195.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.548650026 CEST49820443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.548682928 CEST4434982080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.548739910 CEST4434982080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.549211979 CEST49821443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.549226046 CEST4434982180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.549249887 CEST4434982180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.659889936 CEST49822443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.659934044 CEST4434982280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.660032988 CEST49822443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.667195082 CEST49822443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:18.667212009 CEST4434982280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.667304993 CEST4434982280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:18.767072916 CEST49823443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.767168999 CEST4434982385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.767225981 CEST49824443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.767246008 CEST4434982485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.767271996 CEST49823443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.767334938 CEST49824443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.767940998 CEST49823443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.767976046 CEST4434982385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.768024921 CEST4434982385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.773474932 CEST49824443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.773526907 CEST4434982485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.773653030 CEST4434982485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.780723095 CEST49825443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.780802011 CEST4434982585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.780874968 CEST49825443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.781729937 CEST49825443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:18.781769037 CEST4434982585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.781795979 CEST4434982585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:18.875375032 CEST49826443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.875449896 CEST443498265.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.875564098 CEST49826443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.896231890 CEST49827443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.896321058 CEST443498275.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.896409035 CEST49827443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.896596909 CEST49828443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:18.896644115 CEST443498285.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:18.896787882 CEST49828443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.017666101 CEST49826443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.017710924 CEST443498265.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.017781019 CEST443498265.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.018668890 CEST49827443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.018716097 CEST443498275.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.018878937 CEST443498275.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.019176006 CEST49828443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.019217014 CEST443498285.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.019273996 CEST443498285.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.124918938 CEST49829443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.124991894 CEST4434982980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.125056028 CEST49829443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.125488043 CEST49830443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.125497103 CEST4434983080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.125571966 CEST49830443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.126194000 CEST49831443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.126269102 CEST4434983180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.126411915 CEST49831443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.133898973 CEST49829443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.133924961 CEST4434982980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.133938074 CEST49830443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.133946896 CEST4434983080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.134006977 CEST4434982980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.134018898 CEST4434983080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.134345055 CEST49831443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.134397030 CEST4434983180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.134438992 CEST4434983180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.249458075 CEST49832443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.249526978 CEST4434983280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.249603033 CEST49832443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.250499010 CEST49832443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.250514030 CEST4434983280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.250571966 CEST4434983280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.358815908 CEST49834443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.358820915 CEST49833443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.358865023 CEST4434983480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.358870029 CEST4434983385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.358954906 CEST49834443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.358958960 CEST49833443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.359499931 CEST49835443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.359534979 CEST4434983580.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.359754086 CEST49835443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.359956980 CEST49834443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.359972000 CEST4434983480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.360019922 CEST4434983480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.360333920 CEST49835443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.360335112 CEST49833443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.360344887 CEST4434983580.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.360349894 CEST4434983385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.360382080 CEST4434983580.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.360434055 CEST4434983385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.468327999 CEST49836443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.468394041 CEST4434983685.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.468482971 CEST49836443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.468671083 CEST49837443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.468720913 CEST4434983785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.468770981 CEST49837443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.468890905 CEST49838443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.468928099 CEST443498385.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.468988895 CEST49838443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.469496965 CEST49836443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.469513893 CEST4434983685.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.469559908 CEST49837443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.469572067 CEST4434983785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.469587088 CEST4434983685.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.469760895 CEST4434983785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.470010996 CEST49838443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.470024109 CEST443498385.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.470066071 CEST443498385.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.577696085 CEST49840443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.577702045 CEST49839443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.577775002 CEST443498405.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.577790976 CEST4434983985.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.577789068 CEST49841443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.577861071 CEST443498415.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.577891111 CEST49840443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.577925920 CEST49841443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.578039885 CEST49839443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.578689098 CEST49840443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.578758955 CEST49839443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.578759909 CEST443498405.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.578811884 CEST4434983985.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.578821898 CEST443498405.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.578855038 CEST4434983985.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.578938007 CEST49841443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.578970909 CEST443498415.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.579063892 CEST443498415.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.686861038 CEST49842443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.686908960 CEST443498425.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.686988115 CEST49842443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.687678099 CEST49842443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.687705040 CEST443498425.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.687747002 CEST443498425.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.796380043 CEST49843443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.796427965 CEST4434984380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.796538115 CEST49843443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.797008038 CEST49844443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.797092915 CEST4434984485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.797158003 CEST49844443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.797408104 CEST49845443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.797463894 CEST4434984585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.797523022 CEST49845443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.798095942 CEST49843443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:19.798108101 CEST4434984380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.798152924 CEST4434984380.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:19.798732042 CEST49844443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.798768044 CEST4434984485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.798819065 CEST4434984485.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.799199104 CEST49845443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.799226999 CEST4434984585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.799269915 CEST4434984585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.905689955 CEST49846443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.905694008 CEST49847443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.905769110 CEST4434984785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.905772924 CEST49848443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.905781031 CEST443498465.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.905808926 CEST443498485.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.905843973 CEST49847443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.905888081 CEST49846443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.905993938 CEST49848443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.906610966 CEST49846443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.906646013 CEST443498465.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.906696081 CEST443498465.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.906728029 CEST49847443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:19.906764984 CEST4434984785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.906804085 CEST4434984785.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:19.906932116 CEST49848443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:19.906948090 CEST443498485.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:19.906977892 CEST443498485.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.015024900 CEST49849443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.015064955 CEST4434984980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.015135050 CEST49850443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.015140057 CEST49849443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.015228987 CEST443498505.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.015233994 CEST49851443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.015263081 CEST4434985180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.015299082 CEST49850443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.015312910 CEST49851443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.016016960 CEST49850443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.016058922 CEST443498505.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.016125917 CEST443498505.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.016501904 CEST49851443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.016515970 CEST4434985180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.016623020 CEST4434985180.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.016829967 CEST49849443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.016865969 CEST4434984980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.016896963 CEST4434984980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.124548912 CEST49852443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.124622107 CEST4434985280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.124713898 CEST49852443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.125436068 CEST49852443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.125468969 CEST4434985280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.125519991 CEST4434985280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.233747959 CEST49853443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.233845949 CEST443498535.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.233957052 CEST49853443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.234802961 CEST49853443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.234838963 CEST443498535.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.234891891 CEST443498535.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.343156099 CEST49854443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.343245029 CEST4434985480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.343342066 CEST49854443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.343944073 CEST49854443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.343978882 CEST4434985480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.344038963 CEST4434985480.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.452614069 CEST49855443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:20.452660084 CEST4434985585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:20.452756882 CEST49855443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:20.453484058 CEST49855443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:20.453495026 CEST4434985585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:20.453550100 CEST4434985585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:20.561764956 CEST49856443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.561781883 CEST443498565.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.561896086 CEST49856443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.562335968 CEST49856443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.562345028 CEST443498565.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.562391996 CEST443498565.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.671210051 CEST49857443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.671292067 CEST4434985780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.671365976 CEST49857443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.671783924 CEST49857443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.671814919 CEST4434985780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.671854019 CEST4434985780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.780920029 CEST49858443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:20.781022072 CEST4434985885.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:20.782445908 CEST49858443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:20.789191008 CEST49858443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:20.789228916 CEST4434985885.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:20.789287090 CEST4434985885.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:20.890105963 CEST49859443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.890137911 CEST443498595.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.890666008 CEST49859443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.890885115 CEST49859443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:20.890893936 CEST443498595.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.890950918 CEST443498595.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:20.999300003 CEST49860443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.999412060 CEST4434986080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:20.999500036 CEST49860443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.999944925 CEST49860443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:20.999982119 CEST4434986080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:21.000037909 CEST4434986080.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:21.108978033 CEST49861443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:21.109076977 CEST4434986185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:21.109169006 CEST49861443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:21.109683037 CEST49861443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:21.109720945 CEST4434986185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:21.109807968 CEST4434986185.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:21.328059912 CEST49862443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:21.328109026 CEST4434986280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:21.329202890 CEST49862443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:21.330076933 CEST49862443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:21.330092907 CEST4434986280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:21.330163956 CEST4434986280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:21.501477957 CEST49863443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:21.501540899 CEST4434986385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:21.501635075 CEST49863443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:21.503266096 CEST49863443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:21.503276110 CEST4434986385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:21.503448009 CEST4434986385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:21.609148026 CEST49864443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:21.609231949 CEST443498645.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:21.609318972 CEST49864443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:21.622739077 CEST49864443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:21.622786999 CEST443498645.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:21.622845888 CEST443498645.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:21.857335091 CEST49865443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:21.857434988 CEST4434986585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:21.857527018 CEST49865443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:21.861370087 CEST49865443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:21.861407042 CEST4434986585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:21.861526012 CEST4434986585.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:21.971144915 CEST49866443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:21.971240997 CEST443498665.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:21.971324921 CEST49866443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:21.975065947 CEST49866443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:21.975095987 CEST443498665.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:21.975155115 CEST443498665.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:22.077476978 CEST49867443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:22.077517986 CEST4434986780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:22.077579975 CEST49867443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:22.078161001 CEST49867443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:22.078170061 CEST4434986780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:22.078221083 CEST4434986780.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:22.296547890 CEST49868443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:22.296587944 CEST443498685.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:22.296658039 CEST49868443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:22.297807932 CEST49868443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:22.297822952 CEST443498685.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:22.297955036 CEST443498685.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:22.405556917 CEST49869443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:22.405617952 CEST4434986980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:22.405680895 CEST49869443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:22.406517982 CEST49869443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:22.406539917 CEST4434986980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:22.406662941 CEST4434986980.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:22.515553951 CEST49870443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:22.515592098 CEST4434987085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:22.515681028 CEST49870443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:22.521119118 CEST49870443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:22.521132946 CEST4434987085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:22.521224976 CEST4434987085.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:22.733757973 CEST49871443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:22.733803034 CEST443498715.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:22.734060049 CEST49871443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:22.734535933 CEST49871443192.168.2.45.252.177.228
                            Oct 2, 2024 14:02:22.734571934 CEST443498715.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:22.734631062 CEST443498715.252.177.228192.168.2.4
                            Oct 2, 2024 14:02:22.843053102 CEST49872443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:22.843091011 CEST4434987280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:22.843154907 CEST49872443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:22.843693972 CEST49872443192.168.2.480.87.206.189
                            Oct 2, 2024 14:02:22.843707085 CEST4434987280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:22.843817949 CEST4434987280.87.206.189192.168.2.4
                            Oct 2, 2024 14:02:22.952404976 CEST49873443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:22.952429056 CEST4434987385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:22.952493906 CEST49873443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:22.953083992 CEST49873443192.168.2.485.239.52.252
                            Oct 2, 2024 14:02:22.953095913 CEST4434987385.239.52.252192.168.2.4
                            Oct 2, 2024 14:02:22.953207016 CEST4434987385.239.52.252192.168.2.4
                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                            Oct 2, 2024 14:02:31.782955885 CEST1.1.1.1192.168.2.40x93c0No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                            Oct 2, 2024 14:02:31.782955885 CEST1.1.1.1192.168.2.40x93c0No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false

                            Click to jump to process

                            Click to jump to process

                            Click to dive into process behavior distribution

                            Click to jump to process

                            Target ID:0
                            Start time:08:02:13
                            Start date:02/10/2024
                            Path:C:\Windows\System32\loaddll64.exe
                            Wow64 process (32bit):false
                            Commandline:loaddll64.exe "C:\Users\user\Desktop\lK1DKi27B4.dll"
                            Imagebase:0x7ff75cf40000
                            File size:165'888 bytes
                            MD5 hash:763455F9DCB24DFEECC2B9D9F8D46D52
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Target ID:1
                            Start time:08:02:13
                            Start date:02/10/2024
                            Path:C:\Windows\System32\conhost.exe
                            Wow64 process (32bit):false
                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                            Imagebase:0x7ff7699e0000
                            File size:862'208 bytes
                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Target ID:2
                            Start time:08:02:13
                            Start date:02/10/2024
                            Path:C:\Windows\System32\cmd.exe
                            Wow64 process (32bit):false
                            Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",#1
                            Imagebase:0x7ff6cf750000
                            File size:289'792 bytes
                            MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Target ID:3
                            Start time:08:02:13
                            Start date:02/10/2024
                            Path:C:\Windows\System32\rundll32.exe
                            Wow64 process (32bit):false
                            Commandline:rundll32.exe C:\Users\user\Desktop\lK1DKi27B4.dll,start
                            Imagebase:0x7ff6b9870000
                            File size:71'680 bytes
                            MD5 hash:EF3179D498793BF4234F708D3BE28633
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Target ID:4
                            Start time:08:02:13
                            Start date:02/10/2024
                            Path:C:\Windows\System32\rundll32.exe
                            Wow64 process (32bit):false
                            Commandline:rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",#1
                            Imagebase:0x7ff6b9870000
                            File size:71'680 bytes
                            MD5 hash:EF3179D498793BF4234F708D3BE28633
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Target ID:5
                            Start time:08:02:16
                            Start date:02/10/2024
                            Path:C:\Windows\System32\rundll32.exe
                            Wow64 process (32bit):false
                            Commandline:rundll32.exe "C:\Users\user\Desktop\lK1DKi27B4.dll",start
                            Imagebase:0x7ff6b9870000
                            File size:71'680 bytes
                            MD5 hash:EF3179D498793BF4234F708D3BE28633
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Target ID:6
                            Start time:08:02:19
                            Start date:02/10/2024
                            Path:C:\Windows\System32\rundll32.exe
                            Wow64 process (32bit):false
                            Commandline:rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dll
                            Imagebase:0x7ff6b9870000
                            File size:71'680 bytes
                            MD5 hash:EF3179D498793BF4234F708D3BE28633
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Target ID:7
                            Start time:08:02:19
                            Start date:02/10/2024
                            Path:C:\Windows\System32\rundll32.exe
                            Wow64 process (32bit):false
                            Commandline:rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dll
                            Imagebase:0x7ff6b9870000
                            File size:71'680 bytes
                            MD5 hash:EF3179D498793BF4234F708D3BE28633
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Target ID:8
                            Start time:08:02:22
                            Start date:02/10/2024
                            Path:C:\Windows\System32\rundll32.exe
                            Wow64 process (32bit):false
                            Commandline:rundll32.exe C:\Users\user\AppData\Local\Temp/tmpf193.dll,run C:\Users\user\Desktop\lK1DKi27B4.dll
                            Imagebase:0x7ff6b9870000
                            File size:71'680 bytes
                            MD5 hash:EF3179D498793BF4234F708D3BE28633
                            Has elevated privileges:true
                            Has administrator privileges:true
                            Programmed in:C, C++ or other language
                            Reputation:high
                            Has exited:true

                            Reset < >

                              Execution Graph

                              Execution Coverage:17.9%
                              Dynamic/Decrypted Code Coverage:0%
                              Signature Coverage:3.2%
                              Total number of Nodes:93
                              Total number of Limit Nodes:2
                              execution_graph 960 7ffe133237e0 965 7ffe133237fa 960->965 961 7ffe13323928 984 7ffe133217f4 961->984 963 7ffe13323816 965->961 965->963 966 7ffe1332309f 965->966 967 7ffe133230ca 966->967 971 7ffe133230d5 967->971 988 7ffe1332220d 967->988 971->965 972 7ffe1332324b 1024 7ffe13322267 972->1024 974 7ffe133239a0 __WSAFDIsSet 978 7ffe1332315a 974->978 975 7ffe133217f4 fclose 975->978 977 7ffe13321900 ReleaseMutex 977->978 978->971 978->972 978->974 978->975 978->977 983 7ffe133219e8 ReleaseMutex __WSAFDIsSet 978->983 1001 7ffe13322317 978->1001 1009 7ffe13321c76 978->1009 1013 7ffe13323ac7 978->1013 1017 7ffe133220a9 978->1017 1020 7ffe13322115 978->1020 983->978 985 7ffe13321823 984->985 987 7ffe13321827 985->987 1047 7ffe13323d80 fclose 985->1047 987->963 1028 7ffe13323e78 CreateMutexA 988->1028 990 7ffe1332222e 991 7ffe13323e78 CreateMutexA 990->991 992 7ffe1332224a 991->992 993 7ffe133228d9 992->993 994 7ffe13322934 993->994 995 7ffe13323ac7 __WSAFDIsSet 994->995 996 7ffe13322a4e 995->996 1000 7ffe13322a52 996->1000 1030 7ffe133239a0 996->1030 998 7ffe13322a8b 999 7ffe133217f4 fclose 998->999 998->1000 999->1000 1000->978 1004 7ffe1332233c 1001->1004 1005 7ffe13322348 1001->1005 1036 7ffe13323e28 ReleaseMutex 1004->1036 1005->1004 1006 7ffe13323ac7 __WSAFDIsSet 1005->1006 1007 7ffe133223fc 1006->1007 1007->1004 1008 7ffe13323ac7 __WSAFDIsSet 1007->1008 1008->1004 1010 7ffe13321c9c 1009->1010 1011 7ffe13323e28 ReleaseMutex 1010->1011 1012 7ffe13321d06 1011->1012 1012->978 1014 7ffe13323b07 1013->1014 1016 7ffe13323afd 1013->1016 1015 7ffe13323ef0 __WSAFDIsSet 1014->1015 1014->1016 1015->1016 1016->978 1018 7ffe13322115 2 API calls 1017->1018 1019 7ffe133220b6 1018->1019 1019->978 1021 7ffe1332212d 1020->1021 1022 7ffe133221bb 1020->1022 1021->1022 1038 7ffe133219e8 1021->1038 1022->978 1026 7ffe13322278 1024->1026 1025 7ffe133219e8 2 API calls 1025->1026 1026->1025 1027 7ffe13322297 1026->1027 1027->971 1029 7ffe13348280 1028->1029 1031 7ffe133239e0 1030->1031 1033 7ffe133239d6 1030->1033 1031->1033 1034 7ffe13323ef0 __WSAFDIsSet 1031->1034 1033->998 1035 7ffe133483b8 1034->1035 1037 7ffe133482d0 1036->1037 1039 7ffe13321a0f 1038->1039 1043 7ffe13321a4e 1039->1043 1044 7ffe13322466 1039->1044 1040 7ffe13323e28 ReleaseMutex 1041 7ffe13321c6f 1040->1041 1041->1021 1043->1040 1045 7ffe13322317 2 API calls 1044->1045 1046 7ffe13322499 1045->1046 1046->1043 1048 7ffe13348328 1047->1048 1049 7ffe13322fea 1050 7ffe1332300b 1049->1050 1053 7ffe1332307e 1050->1053 1054 7ffe13322317 2 API calls 1050->1054 1051 7ffe133219e8 2 API calls 1052 7ffe13323097 1051->1052 1053->1051 1054->1050 1055 7ffe13322cbc 1058 7ffe13322d11 1055->1058 1056 7ffe13321c76 ReleaseMutex 1057 7ffe13322e2a 1056->1057 1059 7ffe13322e71 1057->1059 1060 7ffe13322e31 1057->1060 1058->1056 1062 7ffe13322317 2 API calls 1059->1062 1061 7ffe133219e8 2 API calls 1060->1061 1068 7ffe13322e44 1061->1068 1063 7ffe13322ea4 1062->1063 1064 7ffe13322ea8 1063->1064 1070 7ffe13322ee8 1063->1070 1065 7ffe133219e8 2 API calls 1064->1065 1065->1068 1066 7ffe13322fbe 1067 7ffe133219e8 2 API calls 1066->1067 1067->1068 1069 7ffe133239a0 __WSAFDIsSet 1069->1070 1070->1066 1070->1069 1071 7ffe13322317 2 API calls 1070->1071 1071->1070

                              Callgraph

                              • Executed
                              • Not Executed
                              • Opacity -> Relevance
                              • Disassembly available
                              callgraph 0 Function_00007FFE13321F81 1 Function_00007FFE13322781 2 Function_00007FFE13321000 3 Function_00007FFE13323D80 4 Function_00007FFE13321900 32 Function_00007FFE13323E28 4->32 5 Function_00007FFE13323940 6 Function_00007FFE13321640 38 Function_00007FFE1332152F 6->38 7 Function_00007FFE13321E45 8 Function_00007FFE13323AC7 41 Function_00007FFE13323EF0 8->41 9 Function_00007FFE13321788 13 Function_00007FFE133216D0 9->13 10 Function_00007FFE1332220D 44 Function_00007FFE13323E78 10->44 11 Function_00007FFE1332140E 12 Function_00007FFE13323E91 14 Function_00007FFE13321D10 15 Function_00007FFE13323C93 16 Function_00007FFE13322AD2 17 Function_00007FFE13322115 17->11 33 Function_00007FFE133219E8 17->33 18 Function_00007FFE13322317 18->8 18->14 19 Function_00007FFE13323D16 18->19 18->32 37 Function_00007FFE13323BED 18->37 20 Function_00007FFE13321596 20->38 39 Function_00007FFE1332156F 20->39 21 Function_00007FFE133228D9 21->1 21->8 26 Function_00007FFE133239A0 21->26 27 Function_00007FFE133224A0 21->27 42 Function_00007FFE133217F4 21->42 22 Function_00007FFE1332209C 23 Function_00007FFE1332309F 23->4 23->6 23->8 23->10 23->14 23->15 23->17 23->18 23->19 23->21 23->22 23->26 28 Function_00007FFE13321FE3 23->28 29 Function_00007FFE13322267 23->29 31 Function_00007FFE133220A9 23->31 23->33 23->42 43 Function_00007FFE13321C76 23->43 45 Function_00007FFE1332203A 23->45 24 Function_00007FFE13323E21 25 Function_00007FFE133237E0 25->23 25->42 26->41 29->33 30 Function_00007FFE13322466 30->18 31->2 31->17 33->11 33->30 33->32 34 Function_00007FFE13321F2B 35 Function_00007FFE13321D6A 36 Function_00007FFE13322FEA 36->7 36->14 36->18 36->20 36->22 36->33 36->34 40 Function_00007FFE13323E71 42->3 42->13 43->32 46 Function_00007FFE13322CBC 46->0 46->7 46->14 46->16 46->18 46->26 46->28 46->33 46->34 46->43

                              Control-flow Graph

                              Memory Dump Source
                              • Source File: 00000003.00000002.1735405785.00007FFE13321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FFE13320000, based on PE: true
                              • Associated: 00000003.00000002.1735367602.00007FFE13320000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735488176.00007FFE13324000.00000008.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735570438.00007FFE13325000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735634708.00007FFE13348000.00000004.00000001.01000000.00000003.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_3_2_7ffe13320000_rundll32.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: d068ffc1ab48445f0d0a9c54d85b72c63d2bd69f465f13f63e7f3c7fdfbaf26f
                              • Instruction ID: 2be9231d5485ea5428f21597168ab0e1470969b8ee30f8d90b03c0125f402eb2
                              • Opcode Fuzzy Hash: d068ffc1ab48445f0d0a9c54d85b72c63d2bd69f465f13f63e7f3c7fdfbaf26f
                              • Instruction Fuzzy Hash: 2331CC72A04AC18EE7708E66D8407DC33A1F7197B8F01427ADE2C6BBD8DB78D6448744

                              Control-flow Graph

                              Strings
                              Memory Dump Source
                              • Source File: 00000003.00000002.1735405785.00007FFE13321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FFE13320000, based on PE: true
                              • Associated: 00000003.00000002.1735367602.00007FFE13320000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735488176.00007FFE13324000.00000008.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735570438.00007FFE13325000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735634708.00007FFE13348000.00000004.00000001.01000000.00000003.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_3_2_7ffe13320000_rundll32.jbxd
                              Similarity
                              • API ID:
                              • String ID: %s/tmpf193.dll$rundll32.exe %s,run %s$temp
                              • API String ID: 0-1021872635
                              • Opcode ID: 037ff5137c62a1e0d9fe509e1bdb0bac131be7c1cfe5d51d212a6f508c46df2f
                              • Instruction ID: 298bc308244440296458f71edae7543b0ea0c88b70f53633651c7b14083c69eb
                              • Opcode Fuzzy Hash: 037ff5137c62a1e0d9fe509e1bdb0bac131be7c1cfe5d51d212a6f508c46df2f
                              • Instruction Fuzzy Hash: A221FC15F04B869CFE34DB56E8443E82354EF557A4F804076DD5D2B7A5EE2CE244C345

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 21 7ffe1332309f-7ffe133230d3 call 7ffe13323e90 24 7ffe133230df-7ffe1332311b call 7ffe13323ec8 call 7ffe13323ec0 call 7ffe13323ee0 21->24 25 7ffe133230d5-7ffe133230da 21->25 33 7ffe13323142-7ffe1332315f call 7ffe1332220d call 7ffe133228d9 24->33 34 7ffe1332311d-7ffe13323122 24->34 26 7ffe133237d9-7ffe133237df 25->26 43 7ffe13323161-7ffe13323166 33->43 44 7ffe13323186 33->44 36 7ffe13323124-7ffe13323130 call 7ffe13323ee8 34->36 37 7ffe13323138-7ffe1332313d 34->37 36->37 37->26 45 7ffe13323168-7ffe1332316f call 7ffe13323ee8 43->45 46 7ffe1332317c-7ffe13323181 43->46 47 7ffe1332318e-7ffe133231b1 call 7ffe133239a0 44->47 50 7ffe13323174 45->50 46->26 52 7ffe13323790-7ffe13323791 47->52 53 7ffe133231b7-7ffe133231bb 47->53 50->46 54 7ffe1332379a-7ffe1332379f 52->54 53->54 55 7ffe133231c1-7ffe133231c5 53->55 56 7ffe133237a1-7ffe133237ad call 7ffe13323ee8 54->56 57 7ffe133237b5-7ffe133237c8 call 7ffe13323e18 call 7ffe13322267 54->57 55->54 58 7ffe133231cb-7ffe133231f0 call 7ffe13323d16 call 7ffe13323da8 55->58 56->57 69 7ffe133237d4 57->69 70 7ffe133237ca-7ffe133237cf call 7ffe13323e18 57->70 71 7ffe133231f7-7ffe133231ff 58->71 69->26 70->69 73 7ffe13323201-7ffe1332323a call 7ffe133239a0 71->73 74 7ffe13323244 71->74 73->71 82 7ffe1332323c-7ffe13323242 73->82 76 7ffe13323245-7ffe13323249 74->76 78 7ffe1332326f-7ffe13323273 76->78 79 7ffe1332324b-7ffe13323250 76->79 80 7ffe1332327f-7ffe13323284 78->80 81 7ffe13323275-7ffe1332327d 78->81 83 7ffe13323793-7ffe13323794 79->83 84 7ffe13323256-7ffe1332326a call 7ffe13323d90 79->84 86 7ffe13323796-7ffe13323797 80->86 87 7ffe1332328a-7ffe1332329e call 7ffe13323d90 80->87 81->80 85 7ffe133232a3-7ffe133232be call 7ffe13323c93 81->85 82->76 83->54 84->83 94 7ffe13323510-7ffe13323516 85->94 95 7ffe133232c4-7ffe133232d9 call 7ffe13321d10 85->95 86->54 87->86 96 7ffe13323679-7ffe1332367f 94->96 97 7ffe1332351c-7ffe13323531 call 7ffe13321d10 94->97 108 7ffe133232df-7ffe133232fa call 7ffe13321900 95->108 109 7ffe133233a8-7ffe133233b8 call 7ffe13321c76 95->109 99 7ffe13323681-7ffe13323687 96->99 100 7ffe133236cb-7ffe133236d1 96->100 111 7ffe13323642-7ffe1332365e call 7ffe1332209c call 7ffe13321640 97->111 112 7ffe13323537-7ffe13323553 call 7ffe13321900 call 7ffe133220a9 97->112 103 7ffe13323742-7ffe13323747 99->103 104 7ffe1332368d-7ffe13323698 99->104 106 7ffe133236d3-7ffe133236d9 100->106 107 7ffe133236db-7ffe133236e5 call 7ffe133217f4 100->107 103->47 113 7ffe1332374d-7ffe13323761 call 7ffe13323d90 103->113 104->103 110 7ffe1332369e-7ffe133236b3 call 7ffe13321d10 104->110 106->107 114 7ffe13323705-7ffe1332370b 106->114 135 7ffe133236e7-7ffe133236f3 call 7ffe13323ee8 107->135 136 7ffe133236fb-7ffe13323700 call 7ffe13323d78 107->136 133 7ffe13323314-7ffe13323329 call 7ffe133219e8 108->133 134 7ffe133232fc-7ffe13323312 108->134 126 7ffe133233be-7ffe133233cb 109->126 127 7ffe133234cb-7ffe133234f5 call 7ffe13321fe3 call 7ffe13323ac7 109->127 110->103 142 7ffe133236b9-7ffe133236c9 call 7ffe133219e8 110->142 111->103 169 7ffe13323664-7ffe13323674 call 7ffe133219e8 111->169 166 7ffe13323555-7ffe1332356a call 7ffe133219e8 112->166 167 7ffe13323589-7ffe13323599 call 7ffe1332203a 112->167 113->47 114->103 120 7ffe1332370d-7ffe13323713 114->120 120->103 129 7ffe13323715-7ffe13323723 120->129 139 7ffe13323401-7ffe13323476 call 7ffe13323da8 * 2 call 7ffe13323db0 call 7ffe13323d70 126->139 140 7ffe133233cd-7ffe133233e2 call 7ffe133219e8 126->140 127->103 180 7ffe133234fb-7ffe1332350b call 7ffe133219e8 127->180 129->103 143 7ffe13323725-7ffe1332372a 129->143 159 7ffe1332332f-7ffe13323343 call 7ffe13323d90 133->159 160 7ffe13323766-7ffe13323767 133->160 134->133 147 7ffe13323348-7ffe1332336e call 7ffe13322317 134->147 135->136 136->114 139->103 214 7ffe1332347c-7ffe13323491 call 7ffe133219e8 139->214 172 7ffe13323772-7ffe13323773 140->172 173 7ffe133233e8-7ffe133233fc call 7ffe13323d90 140->173 142->103 153 7ffe13323799 143->153 154 7ffe1332372c-7ffe13323740 call 7ffe13323d90 143->154 147->103 174 7ffe13323374-7ffe13323389 call 7ffe133219e8 147->174 153->54 154->153 159->160 160->47 194 7ffe1332377e-7ffe1332377f 166->194 195 7ffe13323570-7ffe13323584 call 7ffe13323d90 166->195 189 7ffe133235d4-7ffe133235f3 call 7ffe13323d70 167->189 190 7ffe1332359b-7ffe133235b5 call 7ffe13322115 call 7ffe133219e8 167->190 169->103 172->47 173->172 199 7ffe1332338f-7ffe133233a3 call 7ffe13323d90 174->199 200 7ffe1332376c-7ffe1332376d 174->200 180->103 208 7ffe133235f5-7ffe1332360a call 7ffe133219e8 189->208 209 7ffe13323629-7ffe1332362e 189->209 220 7ffe13323784-7ffe13323785 190->220 221 7ffe133235bb-7ffe133235cf call 7ffe13323d90 190->221 194->47 195->194 199->200 200->47 222 7ffe13323610-7ffe13323624 call 7ffe13323d90 208->222 223 7ffe1332378a-7ffe1332378b 208->223 209->111 215 7ffe13323630-7ffe13323639 209->215 227 7ffe13323493-7ffe1332349f call 7ffe13323d90 214->227 228 7ffe133234a7-7ffe133234ac 214->228 215->111 219 7ffe1332363b-7ffe1332363f 215->219 219->111 220->47 221->220 222->223 223->47 227->228 232 7ffe133234b2-7ffe133234c6 call 7ffe13323d90 228->232 233 7ffe13323778-7ffe13323779 228->233 232->233 233->47
                              Strings
                              Memory Dump Source
                              • Source File: 00000003.00000002.1735405785.00007FFE13321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FFE13320000, based on PE: true
                              • Associated: 00000003.00000002.1735367602.00007FFE13320000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735488176.00007FFE13324000.00000008.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735570438.00007FFE13325000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735634708.00007FFE13348000.00000004.00000001.01000000.00000003.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_3_2_7ffe13320000_rundll32.jbxd
                              Similarity
                              • API ID:
                              • String ID: liaf
                              • API String ID: 0-3481663875
                              • Opcode ID: 1ee44d9be8b281fd32dc2dfea7af1ef8e28513f8b421b1e04d39b6c80ae3c64e
                              • Instruction ID: e03445c2d84191bff83e83c04a98286fb32f6a97f37f6a0ae938b736c33914c4
                              • Opcode Fuzzy Hash: 1ee44d9be8b281fd32dc2dfea7af1ef8e28513f8b421b1e04d39b6c80ae3c64e
                              • Instruction Fuzzy Hash: 89226E66F08A028DFB209AB680453BC27B0AB55778F100675EE7D777E9DE3CA4818758

                              Control-flow Graph

                              Strings
                              Memory Dump Source
                              • Source File: 00000003.00000002.1735405785.00007FFE13321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FFE13320000, based on PE: true
                              • Associated: 00000003.00000002.1735367602.00007FFE13320000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735488176.00007FFE13324000.00000008.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735570438.00007FFE13325000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735634708.00007FFE13348000.00000004.00000001.01000000.00000003.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_3_2_7ffe13320000_rundll32.jbxd
                              Similarity
                              • API ID:
                              • String ID: 85.239.52.252
                              • API String ID: 0-4133895869
                              • Opcode ID: c8072512862064964766682b891cda1bdd396c7c321a2a9c1efabbdb2c12c2f4
                              • Instruction ID: 6b9bb57b96e6e68da18753aa065872d6bd1fd721c312430b89705bc80b86c751
                              • Opcode Fuzzy Hash: c8072512862064964766682b891cda1bdd396c7c321a2a9c1efabbdb2c12c2f4
                              • Instruction Fuzzy Hash: 72516F62B09A929DFB20DBA6D8403EC3771AB15358F404075DE1DABB99DE7CD544C704

                              Control-flow Graph

                              Strings
                              Memory Dump Source
                              • Source File: 00000003.00000002.1735405785.00007FFE13321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FFE13320000, based on PE: true
                              • Associated: 00000003.00000002.1735367602.00007FFE13320000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735488176.00007FFE13324000.00000008.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735570438.00007FFE13325000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735634708.00007FFE13348000.00000004.00000001.01000000.00000003.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_3_2_7ffe13320000_rundll32.jbxd
                              Similarity
                              • API ID:
                              • String ID: 85.239.52.252
                              • API String ID: 0-4133895869
                              • Opcode ID: 02a0628b6d568bbba06dfb60ffc2c7ea0c403360795a489ee6e44c26b910eddc
                              • Instruction ID: 96d0bf3f3b5fb22d7dd6f4c705a9799a7c78c73c960ef3809fd4f5b80f58c111
                              • Opcode Fuzzy Hash: 02a0628b6d568bbba06dfb60ffc2c7ea0c403360795a489ee6e44c26b910eddc
                              • Instruction Fuzzy Hash: 05319172B09A828FEFB49B2788053F922D19B653B4F008074D92D9B7F9EE2CA5058745

                              Control-flow Graph

                              Memory Dump Source
                              • Source File: 00000003.00000002.1735405785.00007FFE13321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FFE13320000, based on PE: true
                              • Associated: 00000003.00000002.1735367602.00007FFE13320000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735488176.00007FFE13324000.00000008.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735570438.00007FFE13325000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735634708.00007FFE13348000.00000004.00000001.01000000.00000003.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_3_2_7ffe13320000_rundll32.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: a7e99f209dc4062eadb156062b447773cbafa840fde06c7853fffa51e9a8b985
                              • Instruction ID: dfe2f9e6f183e45d57c4ac08334259dd9b3db15610716b88d16f6179aea3a12c
                              • Opcode Fuzzy Hash: a7e99f209dc4062eadb156062b447773cbafa840fde06c7853fffa51e9a8b985
                              • Instruction Fuzzy Hash: 2B413832F04A169DFB60CBA6D9043AC36B0AB547A8F100275DE2C77BE9DF38DA008754

                              Control-flow Graph

                              Memory Dump Source
                              • Source File: 00000003.00000002.1735405785.00007FFE13321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FFE13320000, based on PE: true
                              • Associated: 00000003.00000002.1735367602.00007FFE13320000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735488176.00007FFE13324000.00000008.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735570438.00007FFE13325000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735634708.00007FFE13348000.00000004.00000001.01000000.00000003.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_3_2_7ffe13320000_rundll32.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: 17d85fab76ed55d5e5d39da0a193cf729d0284c3de407aa9a9a78387b25e80df
                              • Instruction ID: 90bf9a50bedecc31e6c96e624132cfbea313561cf146c8bedb11859d5174d670
                              • Opcode Fuzzy Hash: 17d85fab76ed55d5e5d39da0a193cf729d0284c3de407aa9a9a78387b25e80df
                              • Instruction Fuzzy Hash: 2631CC76A08AC18EE7708E6AD8407DC73A1F7197B8F404266EE2C6BBD8DF7496448744

                              Control-flow Graph

                              Memory Dump Source
                              • Source File: 00000003.00000002.1735405785.00007FFE13321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FFE13320000, based on PE: true
                              • Associated: 00000003.00000002.1735367602.00007FFE13320000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735488176.00007FFE13324000.00000008.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735570438.00007FFE13325000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735634708.00007FFE13348000.00000004.00000001.01000000.00000003.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_3_2_7ffe13320000_rundll32.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: 4b633d004639130bec2f3cd2b0d0870f0c693c71f8dca34dc6573a98c76dd782
                              • Instruction ID: a8da39f58551559122463d0384d809ce230daed750e738b8da738b1979cc8b74
                              • Opcode Fuzzy Hash: 4b633d004639130bec2f3cd2b0d0870f0c693c71f8dca34dc6573a98c76dd782
                              • Instruction Fuzzy Hash: 20118073B14B808AF7708B69E41039E6261F79439CF508235EA9C2BB98DF7DC5988B00

                              Control-flow Graph

                              • Executed
                              • Not Executed
                              control_flow_graph 385 7ffe1332220d-7ffe13322266 call 7ffe13323e78 * 2
                              Memory Dump Source
                              • Source File: 00000003.00000002.1735405785.00007FFE13321000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FFE13320000, based on PE: true
                              • Associated: 00000003.00000002.1735367602.00007FFE13320000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735488176.00007FFE13324000.00000008.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735570438.00007FFE13325000.00000002.00000001.01000000.00000003.sdmpDownload File
                              • Associated: 00000003.00000002.1735634708.00007FFE13348000.00000004.00000001.01000000.00000003.sdmpDownload File
                              Joe Sandbox IDA Plugin
                              • Snapshot File: hcaresult_3_2_7ffe13320000_rundll32.jbxd
                              Similarity
                              • API ID:
                              • String ID:
                              • API String ID:
                              • Opcode ID: b30b0dd98c189ec07417ee6450ca6486aab83f3bfc1e95cf89db179afefbdeec
                              • Instruction ID: c45c0335a884dbdee6e101342c4271676df186179c442d18c05863dcd338e334
                              • Opcode Fuzzy Hash: b30b0dd98c189ec07417ee6450ca6486aab83f3bfc1e95cf89db179afefbdeec
                              • Instruction Fuzzy Hash: C1E04622B08F018EF3605B62E8523763298EB68770F104078E52C6B7F1DF3DE8A55748